PT-2026-64295 · Loytec · L-Vis+7

CVE-2026-12496

·

Published

2026-07-24

·

Updated

2026-07-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Loytec LIP-ME201C versions prior to 8.4.17 Loytec L-INX versions prior to 8.4.17 Loytec L-GATE versions prior to 8.4.17 Loytec L-ROC versions prior to 8.4.17 Loytec L-IOB versions prior to 8.4.17 Loytec L-DALI versions prior to 8.4.17 Loytec L-VIS versions prior to 8.4.17 Loytec L-PAD versions prior to 8.4.17
Description Stored Cross-Site Scripting (CWE-79) exists in the OPC XML-DA server statistics. This allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser, potentially leading to session hijacking, credential theft, or device reconfiguration. The issue is triggered via a crafted User-Agent header in a POST /da request.
Recommendations Update Loytec LIP-ME201C to version 8.4.17 or later. Update Loytec L-INX to version 8.4.17 or later. Update Loytec L-GATE to version 8.4.17 or later. Update Loytec L-ROC to version 8.4.17 or later. Update Loytec L-IOB to version 8.4.17 or later. Update Loytec L-DALI to version 8.4.17 or later. Update Loytec L-VIS to version 8.4.17 or later. Update Loytec L-PAD to version 8.4.17 or later.

Fix

XSS

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12496

Affected Products

L-Dali
L-Gate
L-Inx
L-Iob
L-Pad
L-Roc
L-Vis
Lip-Me201