LOYTEC LINX-212 firmware 6.2.4 and LVIS-3ME12-A1 firmware...
High severity
Unreviewed
Published
Nov 5, 2023
to the GitHub Advisory Database
•
Updated Sep 19, 2024
Description
Published by the National Vulnerability Database
Nov 4, 2023
Published to the GitHub Advisory Database
Nov 5, 2023
Last updated
Sep 19, 2024
LOYTEC LINX-212 firmware 6.2.4 and LVIS-3ME12-A1 firmware 6.2.2 and LIOB-586 firmware 6.2.3 devices lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.
References