Buffer Overflow Vulnerability in GALAYOU Y4 Web Server by GALAYOU
CVE-2026-12192

8.7HIGH

Key Information:

Vendor

Galayou

Status
Vendor
CVE Published:
14 June 2026

What is CVE-2026-12192?

A vulnerability has been identified in GALAYOU Y4 version 1.0.0, which affects a specific function within the Web Server component. This security flaw enables a buffer overflow condition that can be exploited by an attacker within the local network. It's important to note that this exploit has been publicly disclosed, raising concerns about its potential use. Despite early notifications to the vendor regarding this issue, there has been no response to address the vulnerability.

Affected Version(s)

Y4 1.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd0 (VulDB User)
VulDB CNA Team
.