PatchSiren

Loytec CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Loytec CVE published 2026-07-24

CVE-2026-55730

CVE-2026-55730 is a Reflected Cross-Site Scripting (CWE-79) vulnerability in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms. This vulnerability allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter. The vulnerability exists due to [truncated]

HIGH Loytec CVE published 2026-07-24

CVE-2026-55729

The CVE record for CVE-2026-55729 was published on 2026-07-24T15:18:31.120Z and is currently listed as Deferred on the NVD. This vulnerability, identified as Exposure of Sensitive Information (CWE-200), affects Loytec LWEB-802 versions prior to 5.0.8. An unauthenticated remote attacker can exploit this issue by crafting a link to leak stored management credentials from the browser's localStorage. Users of [truncated]