CVE-2026-55731
Received Received - Intake

Unauthenticated Remote DoS in Loytec LINX Devices via SNMP GETNEXT

Vulnerability report for CVE-2026-55731, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Switzerland Government Common Vulnerability Program

Description

Unchecked input for loop condition (CWE-606)Β in the SNMP agent in Loytec LIP-ME201C,Β L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
loytec lip-me201c 8.4.16
loytec l-inx 8.4.16
loytec l-gate 8.4.16
loytec l-roc 8.4.16
loytec l-iob 8.4.16
loytec l-dali 8.4.16
loytec l-vis 8.4.16
loytec l-pad 8.4.16
loytec l-web 8.4.16
loytec l-roc to 8.4.18 (inc)
loytec l-inx to 8.4.18 (inc)
loytec l-gate to 8.4.18 (inc)
loytec l-iob to 8.4.18 (inc)
loytec l-dali to 8.4.18 (inc)
loytec l-vis to 8.4.18 (inc)
loytec l-pad to 8.4.18 (inc)
loytec l-web to 8.4.18 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-606 The product does not properly check inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unchecked input for loop condition (CWE-606) in the SNMP agent of Loytec devices. An unauthenticated remote attacker can exploit it by sending a crafted SNMP GETNEXT request with a large OID component, causing persistent denial of service through CPU exhaustion.

Detection Guidance

Monitor network traffic for unusually large SNMP GETNEXT requests targeting Loytec devices. Check CPU usage spikes on affected systems. Inspect SNMP logs for malformed OID components or repeated requests from the same source.

Impact Analysis

The vulnerability can disrupt SNMP database functionality and cause persistent denial of service, leading to system unavailability. Affected systems include Loytec building management and automation devices running firmware versions up to 8.4.16.

Compliance Impact

This vulnerability primarily causes persistent denial of service (DoS) via CPU exhaustion, disrupting SNMP database functionality. It does not directly affect data confidentiality or integrity but may impact system availability, which is a key requirement under GDPR (Article 32) and HIPAA (Security Rule). Prolonged downtime could lead to non-compliance if critical systems are affected.

Mitigation Strategies

Upgrade affected Loytec devices to firmware version 8.4.18 or later. Block external SNMP traffic at the firewall if not required. Disable SNMP if possible or restrict access to trusted IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55731. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart