CVE-2026-55732
Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.
| CWE | CWE-125 |
| Vendor | loytec |
| Product | lip-me20xc |
| Published | Jul 24, 2026 |
| Last Updated | Jul 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for loytec lip-me20xc
Be the first to know when new unknown vulnerabilities affecting loytec lip-me20xc are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Loytec / LIP-ME20xC
0 ≤ 8.4.18
Loytec / L-INX
0 ≤ 8.4.18
Loytec / L-GATE
0 ≤ 8.4.18
Loytec / L-ROC
0 ≤ 8.4.18
Loytec / L-IOB
0 ≤ 8.4.18
Loytec / L-DALI
0 ≤ 8.4.18
Loytec / L-VIS
0 ≤ 8.4.18
Loytec / L-PAD
0 ≤ 8.4.18
References
Credits
Daniel Hulliger, armasuisse CYD Campus Damian Pfammatter, armasuisse CYD Campus