Impact
The flaw is a reflected Cross‑Site Scripting (CWE‑79) vulnerability in Loytec LWEB‑802 that allows an unauthenticated remote attacker to craft a link containing a malicious “project” or “mspParams” parameter. When the victim visits the link, the attacker’s payload is executed in the victim’s browser with the victim’s privileges, potentially enabling the attacker to perform actions or steal sensitive information. The impact is client‑side code execution, providing the attacker with the victim’s browser context but not direct server‑side compromise.
Affected Systems
All platforms running Loytec LWEB‑802 firmware before version 5.0.8 are affected. The vulnerability exists in the web interface of this product. No specific operating system or hardware variant restriction is mentioned beyond "all platforms."
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Although the EPSS score is listed as < 1%, indicating a low but non‑zero exploitation probability, the lack of authentication and the simplicity of triggering the flaw via a crafted URL make it a likely target in phishing or social‑engineering campaigns. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no confirmed public exploits have surfaced yet. The likely attack surface is a user‑initiated, URL‑based vector that can be distributed through email, chat, or compromised sites.
OpenCVE Enrichment