Junglewise Threat Intelligence

CVE-2026-55731: Loytec Multiple Products DoS via SNMP Agent CPU Exhaustion

CVE-2026-55731 · Severity: info · CVSS 6.6 · Published 2026-07-24

Technologies: LOYTEC L-DALI, LOYTEC L-INX, LOYTEC L-PAD, LOYTEC LIP-ME201C, LOYTEC L-IOB, LOYTEC L-GATE, LOYTEC L-VIS, LOYTEC L-ROC. Vendors: LOYTEC.

Executive brief

A vulnerability exists in the SNMP management component of several Loytec building automation and control devices. An unauthenticated attacker can remotely send a specially crafted network request to these devices, causing them to consume excessive processor resources. This results in a persistent denial of service, making the building management systems unresponsive and disrupting operations.

Technical details

A vulnerability classified as CWE-606 (Unchecked Input for Loop Condition) exists in the SNMP agent of Loytec firmware through version 8.4.16 on LINX-A64 platforms. The flaw is triggered by a crafted SNMP GETNEXT request containing a large OID component. Because the agent does not properly validate the input used in loop conditions, processing the request leads to CPU exhaustion. This allows a remote, unauthenticated attacker to cause a persistent denial of service. The issue is resolved in firmware version 8.4.18.

Affected products

  • Loytec LIP-ME201C through 8.4.16
  • Loytec L-INX through 8.4.16
  • Loytec L-GATE through 8.4.16
  • Loytec L-ROC through 8.4.16
  • Loytec L-IOB through 8.4.16
  • Loytec L-DALI through 8.4.16
  • Loytec L-VIS through 8.4.16
  • Loytec L-PAD through 8.4.16

Timeline

  • 2026-07-24: advisory
  • 2026-07-24: disclosed

References

Related threats