Description
Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
Published: 2026-07-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stored Cross‑Site Scripting (CWE-79) and Input/Output Encoding (CWE-116) in the OPC XML‑DA server statistics allows an unauthenticated remote attacker to inject and execute arbitrary JavaScript in an administrator's browser through a crafted User‑Agent header in a POST /da request, enabling session hijacking, credential theft, and device reconfiguration.

Affected Systems

The vulnerability affects Loytec devices LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑PAD, L‑VIS up to and including 8.4.16. Firmware 8.4.18 contains the official fix.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Attackers could exploit the weakness remotely over the network via a crafted OPC XML‑DA server; authentication is not required to inject the malicious payload.

Generated by OpenCVE AI on August 3, 2026 at 20:17 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 8.4.18.


OpenCVE Recommended Actions

  • Upgrade the device firmware to version 8.4.18 or later.
  • Restrict the OPC XML‑DA server to trusted IP ranges and enforce authentication before accepting requests.
  • Close or firewall the OPC XML‑DA port on publicly exposed interfaces, only allowing traffic through a secured VPN or internal network.

Generated by OpenCVE AI on August 3, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc
Vendors & Products Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.
Title Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server
Weaknesses CWE-116
CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T15:01:17.030Z

Reserved: 2026-06-17T08:57:07.049Z

Link: CVE-2026-12496

cve-icon Vulnrichment

Updated: 2026-07-24T15:01:09.205Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:17:08.663

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12496

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-116

    Improper Encoding or Escaping of Output

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')