Impact
The vulnerability allows an unauthenticated remote attacker to retrieve stored management credentials from browser localStorage through a crafted link, resulting in potential compromise of the device’s management interface. The weakness corresponds to Information Exposure (CWE‑200) and leads to unauthorized credential leakage.
Affected Systems
All Loytec LWEB-802 devices running a version earlier than 5.0.8 on any supported platform are affected; the flaw exists within the browser component that stores credentials in localStorage.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, while the EPSS score of less than 1 % suggests a low exploitation probability at the time of analysis. The flaw is not listed in the CISA KEV catalog. A remote attacker can exploit the issue by creating or distributing a malicious link that accesses the browser’s localStorage, which is possible from any network that can reach the device, and the attack requires no prior authentication.
OpenCVE Enrichment