Impact
An unchecked loop condition in the SNMP agent firmware allows an unauthenticated attacker to send a crafted SNMP GETNEXT request with an excessively large OID component. The resulting infinite or overly long loop consumes CPU resources, causing a persistent denial of service. The flaw is a classic input validation failure (CWE‑606).
Affected Systems
The vulnerability affects Loytec LINX devices running firmware 8.4.16 or earlier, including the LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑VIS and L‑PAD models. The affected products are grouped under the Loytec brand and listed as L‑DALI, L‑GATE, L‑INX, L‑IOB, L‑PAD, L‑ROC, L‑VIS, and LIP‑ME20xC. Firmware must be upgraded to version 8.4.18 or later to contain the fix.
Risk and Exploitability
With a CVSS score of 6.6, the risk is classified as moderate. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, an attacker can remotely trigger the CPU exhaustion by sending a single malicious SNMP request from any machine that can reach the target device over the network, without requiring credentials or privileged access.
OpenCVE Enrichment