← Back

CVE-2023-46381

nvd nist
Published: Nov 4, 2023Modified: Nov 4, 2025

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Exploitability: 3.9 / Impact: 4.2
Source: NVD

Description

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

Affected (3)

3 products
Linx 212 Firmware
Lvis 3me12 A1 Firmware
Liob 586 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.2.4
Running on/withPlatform Versions
Loytec
Linx 212
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.2.2
Running on/withPlatform Versions
Loytec
Lvis 3me12 A1
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 6.2.3
Running on/withPlatform Versions
Loytec
Liob 586
All versions

Timeline

No history available yet.