SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55729

HIGH · CVSS 7.7 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Loytec LWEB-802 versions prior to 5.0.8 are vulnerable due to improper handling of `localStorage`, which exposes sensitive management credentials to unauthenticated remote attackers through specially crafted links. This vulnerability can lead to unauthorized access and potential manipulation of the system. Organizations using affected versions should prioritize patching to safeguard against credential leakage and unauthorized access.

CVE
CVE-2026-55729
Severity
HIGH
CVSS
7.7
EPSS
0.32%

Original NVD Description

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.