PT-2026-64304 · Loytec · L-Dali+7
CVE-2026-55732
·
Published
2026-07-24
·
Updated
2026-07-24
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Out-of-bounds Read (CWE-125) in BACnet packet parsing (
bacdt datetime to tod) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash linx a64.exe and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
L-Dali
L-Gate
L-Inx
L-Iob
L-Pad
L-Roc
L-Vis
Lip-Me20Xc