PatchSiren

Loytec CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Loytec CVE published 2026-07-24

CVE-2026-55732

A high-severity Out-of-bounds Read vulnerability, CVE-2026-55732, was found in BACnet packet parsing of various Loytec products. This issue allows an unauthenticated remote attacker to crash the device by sending a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet. The vulnerability affects Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD products through versi [truncated]

MEDIUM Loytec CVE published 2026-07-24

CVE-2026-55731

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-24T15:18:31.393Z and has not been modified since then. The NVD entry is currently Deferred. Organizations using Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD through 8.4.16 should prioritize patching to prevent potential denial-of-service attacks. This vulnerability, an un [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-55730

CVE-2026-55730 is a Reflected Cross-Site Scripting (CWE-79) vulnerability in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms. This vulnerability allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter. The vulnerability exists due to [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-55729

The CVE record for CVE-2026-55729 was published on 2026-07-24T15:18:31.120Z and is currently listed as Deferred on the NVD. This vulnerability, identified as Exposure of Sensitive Information (CWE-200), affects Loytec LWEB-802 versions prior to 5.0.8. An unauthenticated remote attacker can exploit this issue by crafting a link to leak stored management credentials from the browser's localStorage. Users of [truncated]

LOW Loytec CVE published 2026-07-24

CVE-2026-55728

CVE-2026-55728 is a Stack-based Buffer Overflow vulnerability in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD through 8.4.16 on LINX-A64. This vulnerability allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long interface-name argument. The vulnerability has a CVSS [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-12504

CVE-2026-12504 is an Improper Authentication vulnerability in the PAM configuration of various Loytec products, including LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD, through version 8.4.16 on LINX-A64. This vulnerability allows a local attacker to authenticate as a uid=0 account without a password, potentially leading to a root shell via an `/etc/passwd` entry with an empty password [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-12502

CVE-2026-12502 is an Improper Privilege Management vulnerability in `/usr/bin/ltsudo` affecting Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD through 8.4.16 on LINX-A64. A `superadmin`-group attacker can reset the password of any LARM user, including the `larmapp` service account, via the `set-passwd` subcommand. This vulnerability allows for potential privilege escalation and s [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-12496

CVE-2026-12496 is a Stored Cross-Site Scripting (CWE-79) vulnerability in the OPC XML-DA server statistics of various Loytec products. The vulnerability allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser via a crafted 'User-Agent' header in a 'POST /da' request. This could lead to session hijacking, credential theft, and device reconfiguration. The CVE [truncated]