Junglewise Threat Intelligence

CVE-2026-55732: Loytec BACnet devices out-of-bounds read in bacdt_datetime_to_tod

CVE-2026-55732 · Severity: info · CVSS 8.7 · Published 2026-07-24

Technologies: LOYTEC L-DALI, LOYTEC L-INX, LOYTEC L-PAD, LOYTEC LIP-ME201C, LOYTEC L-IOB, LOYTEC L-GATE, LOYTEC L-VIS, LOYTEC L-ROC. Vendors: LOYTEC.

Executive brief

Loytec building automation and control devices are vulnerable to a remote attack that can cause them to crash and reboot. By sending a specially crafted network packet, an unauthenticated attacker can disrupt core building services, leading to a denial of service. This affects various automation servers, touch panels, and lighting controllers used in commercial building management.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the BACnet packet parsing component of multiple Loytec products. The flaw is located in the `bacdt_datetime_to_tod` function, where an invalid month value in a BACnet TimeSynchronization or UTC-TimeSynchronization packet triggers an out-of-bounds read against the `bacdt_days_till_month` lookup table. This causes the `linx_a64.exe` process to crash. Because this process provides core services, repeated crashes lead to a full device reboot. The vulnerability is exploitable over the network without authentication. Firmware version 8.4.20 has been released to mitigate this issue.

Affected products

  • Loytec LIP-ME201C through 8.4.18
  • Loytec L-INX through 8.4.18
  • Loytec L-GATE through 8.4.18
  • Loytec L-ROC through 8.4.18
  • Loytec L-IOB through 8.4.18
  • Loytec L-DALI through 8.4.18
  • Loytec L-VIS through 8.4.18
  • Loytec L-PAD through 8.4.18

Timeline

  • 2026-07-24: advisory: NVD and vendor advisory published
  • 2026-07-24: patched: Firmware version 8.4.20 released

References

Related threats