CyberRota Analysis
AI-GeneratedLoytec LWEB-802 versions prior to 5.0.8 are vulnerable due to improper handling of `localStorage`, which exposes sensitive management credentials to unauthenticated remote attackers through specially crafted links. This vulnerability can lead to unauthorized access and potential manipulation of the system. Organizations using affected versions should prioritize patching to safeguard against credential leakage and unauthorized access.
CVE
CVE-2026-55729
Severity
HIGH
CVSS
7.7
EPSS
0.32%
Original NVD Description
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.