Impact
Stored Cross‑Site Scripting (CWE-79) and Input/Output Encoding (CWE-116) in the OPC XML‑DA server statistics allows an unauthenticated remote attacker to inject and execute arbitrary JavaScript in an administrator's browser through a crafted User‑Agent header in a POST /da request, enabling session hijacking, credential theft, and device reconfiguration.
Affected Systems
The vulnerability affects Loytec devices LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑PAD, L‑VIS up to and including 8.4.16. Firmware 8.4.18 contains the official fix.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score of <1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Attackers could exploit the weakness remotely over the network via a crafted OPC XML‑DA server; authentication is not required to inject the malicious payload.
OpenCVE Enrichment