PT-2026-64301 · Loytec · Lweb-802
CVE-2026-55729
·
Published
2026-07-24
·
Updated
2026-07-27
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Loytec LWEB-802 versions prior to 5.0.8
Description
An issue exists where sensitive information is exposed within the browser
localStorage. This allows an unauthenticated remote attacker to leak stored management credentials by using a crafted link.Recommendations
Update Loytec LWEB-802 to version 5.0.8 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lweb-802