LOYTEC LWEB-802是LOYTEC公司的一款自动化控制网关。 LOYTEC LWEB-802 5.0.8之前版本存在信息泄露漏洞,该漏洞源于浏览器localStorage存储的管理员凭据泄露,可能导致未经身份验证的远程攻击者通过特制链接泄露存储的管理凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12503 | 9.2 CRITICAL | Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter |
| CVE-2026-12496 | 8.7 HIGH | Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server |
| CVE-2026-55730 | 8.7 HIGH | Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802 |
| CVE-2026-55732 | 8.7 HIGH | Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod) |
| CVE-2026-12502 | 8.4 HIGH | Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo |
| CVE-2026-12504 | 8.4 HIGH | Loytec LINX firmware: Improper Authentication in PAM configuration |
| CVE-2026-55731 | 6.6 MEDIUM | Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent |
| CVE-2026-55728 | 3.8 LOW | Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict |
No comments yet