SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55732

HIGH · CVSS 8.7 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Loytec devices, including the LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD, are vulnerable to an out-of-bounds read issue in BACnet packet parsing, which can be exploited by unauthenticated remote attackers. By sending a malformed BACnet TimeSynchronization packet with an invalid month value, an attacker can crash the `linx_a64.exe` process, potentially leading to device reboot and service disruption. Organizations using these Loytec products should prioritize patching to mitigate the risk of remote exploitation and ensure operational continuity.

CVE
CVE-2026-55732
Severity
HIGH
CVSS
8.7
EPSS
0.32%

Original NVD Description

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.