Executive brief
Loytec building automation and control devices are vulnerable to a remote attack that can cause them to crash and reboot. By sending a specially crafted network packet, an unauthenticated attacker can disrupt core building services, leading to a denial of service. This affects various automation servers, touch panels, and lighting controllers used in commercial building management.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the BACnet packet parsing component of multiple Loytec products. The flaw is located in the `bacdt_datetime_to_tod` function, where an invalid month value in a BACnet TimeSynchronization or UTC-TimeSynchronization packet triggers an out-of-bounds read against the `bacdt_days_till_month` lookup table. This causes the `linx_a64.exe` process to crash. Because this process provides core services, repeated crashes lead to a full device reboot. The vulnerability is exploitable over the network without authentication. Firmware version 8.4.20 has been released to mitigate this issue.
Affected products
- Loytec LIP-ME201C through 8.4.18
- Loytec L-INX through 8.4.18
- Loytec L-GATE through 8.4.18
- Loytec L-ROC through 8.4.18
- Loytec L-IOB through 8.4.18
- Loytec L-DALI through 8.4.18
- Loytec L-VIS through 8.4.18
- Loytec L-PAD through 8.4.18
Timeline
- 2026-07-24: advisory: NVD and vendor advisory published
- 2026-07-24: patched: Firmware version 8.4.20 released