PT-2026-64304 · Loytec · L-Dali+7

CVE-2026-55732

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Out-of-bounds Read (CWE-125) in BACnet packet parsing (bacdt datetime to tod) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash linx a64.exe and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55732

Affected Products

L-Dali
L-Gate
L-Inx
L-Iob
L-Pad
L-Roc
L-Vis
Lip-Me20Xc