Executive brief
Loytec LWEB-802 is a building management and automation software used to control lighting, heating, and other facility systems. A security flaw allows an attacker to steal saved login credentials if they can trick a user into clicking a malicious link. If successful, the attacker could gain full administrative access to the building's management systems, potentially disrupting operations or compromising facility security.
Technical details
A vulnerability classified as CWE-200 (Exposure of Sensitive Information) exists in the LWEB802 browser interface. The application stores project credentials in the browser's `localStorage` in a manner that allows them to be accessed by an unauthorized actor. An unauthenticated remote attacker can exploit this by inducing a legitimate user to visit a specially crafted link (requiring user interaction). Successful exploitation results in the disclosure of valid usernames and passwords, which can be used to authenticate to the management web application. The issue is resolved in LWEB-802 version 5.0.8.
Affected products
- Loytec LWEB-802 before 5.0.8
Timeline
- 2026-07-24: advisory: NVD and vendor advisory published
- 2026-07-24: patched: Fix available in version 5.0.8