CVE-2026-55732
Received Received - Intake

Out-of-bounds Read in Loytec LIP-ME201C and Other Products

Vulnerability report for CVE-2026-55732, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: Switzerland Government Common Vulnerability Program

Description

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
loytec lip-me201c 8.4.18
loytec l-inx 8.4.18
loytec l-gate 8.4.18
loytec l-roc 8.4.18
loytec l-iob 8.4.18
loytec l-dali 8.4.18
loytec l-vis 8.4.18
loytec l-pad 8.4.18
loytec linx-a64 8.4.18

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read (CWE-125) in the BACnet packet parsing function bacdt_datetime_to_tod. It affects multiple Loytec devices running firmware versions up to 8.4.18. An unauthenticated remote attacker can exploit it by sending a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. This causes the device to crash due to reading outside the bounds of the bacdt_days_till_month lookup table.

Detection Guidance

Monitor network traffic for malformed BACnet TimeSynchronization or UTC-TimeSynchronization packets with invalid month values. Use packet inspection tools like Wireshark to filter for BACnet protocol traffic and check for unusual or malformed packets targeting port 47808 (default BACnet port).

Impact Analysis

The vulnerability allows an attacker to crash the linx_a64.exe process on affected devices, leading to a denial of service. While the process auto-restarts after each crash, repeated exploitation can disrupt device functions and eventually force a full device reboot. This can cause operational downtime in building management, automation, or control systems.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by enabling denial-of-service attacks that disrupt device availability. Repeated crashes of BACnet devices may lead to loss of control over building management systems, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade affected Loytec devices to firmware version 8.4.20 or later to address the out-of-bounds read vulnerability. Isolate vulnerable devices from untrusted networks until patched. Monitor device logs for repeated crashes of linx_a64.exe which may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55732. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart