Description
Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.
Published: 2026-07-24
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated remote attacker to retrieve stored management credentials from browser localStorage through a crafted link, resulting in potential compromise of the device’s management interface. The weakness corresponds to Information Exposure (CWE‑200) and leads to unauthorized credential leakage.

Affected Systems

All Loytec LWEB-802 devices running a version earlier than 5.0.8 on any supported platform are affected; the flaw exists within the browser component that stores credentials in localStorage.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1 % suggests a low exploitation probability at the time of analysis. The flaw is not listed in the CISA KEV catalog. A remote attacker can exploit the issue by creating or distributing a malicious link that accesses the browser’s localStorage, which is possible from any network that can reach the device, and the attack requires no prior authentication.

Generated by OpenCVE AI on August 3, 2026 at 20:15 UTC.

Remediation

Vendor Solution

Update to LWEB-802 version 5.0.8.


OpenCVE Recommended Actions

  • Apply the vendor‑issued update to LWEB‑802 version 5.0.8 or newer.
  • Restrict the use of localStorage for storing credentials or remove any credential storage from the browser context.
  • Implement server‑side controls to ensure that only authenticated users can trigger actions that read localStorage and audit all links that gain access to the browser to prevent unauthorized execution.

Generated by OpenCVE AI on August 3, 2026 at 20:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec lweb-802
Vendors & Products Loytec
Loytec lweb-802

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.
Title Loytec LWEB802: Exposure of Sensitive Information in browser localStorage
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T14:55:29.967Z

Reserved: 2026-06-17T09:48:05.268Z

Link: CVE-2026-55729

cve-icon Vulnrichment

Updated: 2026-07-24T14:55:24.954Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:18:31.120

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-55729

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor