Junglewise Threat Intelligence

CVE-2026-20797: A stack based buffer overflow exists in an API route of XWEB Pro version 1.12.1 and prior, enabling unauthenticated attackers to cause stac

CVE-2026-20797 · Severity: medium · CVSS 4.3 · Published 2026-02-27

Technologies: Copeland Xweb 500b Pro Firmware, Copeland Xweb 500d Pro Firmware, Copeland Xweb 500b Pro, Copeland Xweb 300d Pro Firmware, Copeland Xweb 300d Pro, Copeland Xweb 500d Pro. Vendors: Copeland.

Executive brief

Copeland XWEB Pro is an industrial monitoring and control solution used to manage refrigeration and HVAC systems. A security flaw in its web interface allows an unauthenticated attacker to crash the software by sending a specially crafted request. This can lead to a loss of monitoring capabilities and service disruption for the managed industrial equipment.

Technical details

A stack-based buffer overflow (CWE-121) exists within an API route of the Copeland XWEB Pro web interface. The vulnerability is caused by improper bounds checking when processing input, allowing an unauthenticated attacker to cause stack corruption. While some assessments suggest a high impact (CVSS 9.8), the primary reported impact from ICS-CERT is a program termination leading to a denial-of-service (DoS) condition. The attack can be executed over the network without user interaction. Copeland has released updates to address this and several other vulnerabilities in the XWEB Pro series.

Affected products

  • Copeland XWEB 300D PRO <=1.12.1
  • Copeland XWEB 500D PRO <=1.12.1
  • Copeland XWEB 500B PRO <=1.12.1

Timeline

  • 2026-02-26: advisory: CISA/ICS-CERT published advisory ICSA-26-057-10
  • 2026-02-27: disclosed: CVE published to NVD

References

Related threats