Junglewise Threat Intelligence

CVE-2026-12496: Loytec Multiple Products Stored XSS in OPC XML-DA Server Statistics

CVE-2026-12496 · Severity: info · CVSS 8.7 · Published 2026-07-24

Technologies: LOYTEC L-DALI, LOYTEC L-INX, LOYTEC L-PAD, LOYTEC LIP-ME201C, LOYTEC L-IOB, LOYTEC L-GATE, LOYTEC L-VIS, LOYTEC L-ROC. Vendors: LOYTEC.

Executive brief

Loytec automation and building management devices are vulnerable to a security flaw where malicious code can be stored on the device by an unauthenticated user. When an administrator later views the device's server statistics page, this code executes in their browser. This could allow an attacker to hijack administrative sessions, steal login credentials, or change device configurations, potentially disrupting building operations.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the OPC XML-DA server endpoint (/da) of multiple Loytec building automation products. The server logs incoming SOAP requests and displays client metadata, specifically the User-Agent header, on the statistics page (/webui/statistics/opc_srv) without proper sanitization or output encoding. An unauthenticated remote attacker can inject malicious JavaScript via a crafted User-Agent header in a POST request. The payload is executed when an authenticated administrator views the statistics page, potentially leading to session hijacking or full device reconfiguration. The vulnerability is addressed in firmware version 8.4.18.

Affected products

  • Loytec LIP-ME201C through 8.4.16
  • Loytec L-INX through 8.4.16
  • Loytec L-GATE through 8.4.16
  • Loytec L-ROC through 8.4.16
  • Loytec L-IOB through 8.4.16
  • Loytec L-DALI through 8.4.16
  • Loytec L-VIS through 8.4.16
  • Loytec L-PAD through 8.4.16

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats