Description
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.
Published: 2026-07-24
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read (CWE‑125) in the BACnet packet parsing function bacdt_datetime_to_tod. A malformed TimeSynchronization or UTC‑TimeSynchronization packet with an invalid month value can trigger a crash of linx_a64.exe, which in turn causes the device to reboot. This allows an unauthenticated remote attacker to destabilize the device’s availability without needing any credentials.

Affected Systems

Affected products include Loytec LIP‑ME201C, L‑INX, L‑GATE, L‑ROC, L‑IOB, L‑DALI, L‑VIS, and L‑PAD running LINX firmware up to version 8.4.18. Upgrading to firmware 8.4.20 or later resolves the issue for all listed devices.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over BACnet; an unauthenticated attacker only needs to send a crafted TimeSynchronization packet to the device’s BACnet port.

Generated by OpenCVE AI on August 3, 2026 at 20:14 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 8.4.20.


OpenCVE Recommended Actions

  • Apply the official firmware upgrade to version 8.4.20 or later on all affected devices.
  • Restrict or block BACnet TimeSynchronization and UTC‑TimeSynchronization traffic to the device using firewall rules or network segmentation until the patch is deployed.
  • If an immediate patch is not possible, disable BACnet TimeSynchronization functionality or configure the device to reject malformed packets if the option is available.

Generated by OpenCVE AI on August 3, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc
Vendors & Products Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.
Title Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T14:53:49.184Z

Reserved: 2026-06-17T09:48:05.268Z

Link: CVE-2026-55732

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:18:31.543

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-55732

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:15:04Z

Weaknesses