CVE-2026-55729 PUBLISHED

Loytec LWEB802: Exposure of Sensitive Information in browser localStorage

Assigner: NCSC.ch
Reserved: 17.06.2026 Published: 24.07.2026 Updated: 24.07.2026

Exposure of Sensitive Information (CWE-200) in LWEB802 browser localStorage in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.7

Product Status

Vendor Loytec
Product LWEB-802
Versions Default: unaffected
  • affected from 0 to 5.0.8 (excl.)

Solutions

Update to LWEB-802 version 5.0.8.

Credits

  • Daniel Hulliger, armasuisse CYD Campus finder
  • Damian Pfammatter, armasuisse CYD Campus finder

References

Problem Types

  • CWE-200 Exposure of sensitive information to an unauthorized actor CWE

Impacts

  • CAPEC-98 Phishing
  • CAPEC-173 Action Spoofing