CVE-2026-12496
Loytec · LIP-ME20xC, L-INX, L-GATE, L-ROC, L-IOB, L-DALI
A stored cross-site scripting (XSS) vulnerability in the OPC XML-DA server statistics of various Loytec devices allows unauthenticated attackers to execute malicious scripts in a user's browser.
Executive summary
A stored cross-site scripting vulnerability in multiple Loytec products allows unauthenticated attackers to execute arbitrary scripts in the context of an administrative session.
Vulnerability
This is a stored XSS vulnerability (CWE-79) triggered by improper neutralization of input within the OPC XML-DA server statistics. The vulnerability is exploitable by an unauthenticated attacker, though it requires a user to interact with the malicious content.
Business impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the victim's browser session. This can be used to steal session cookies, perform unauthorized actions on behalf of an administrator, or redirect users to malicious sites, potentially leading to full device compromise. Given the CVSS score of 8.7, this vulnerability represents a high risk to operational technology environments.
Remediation
Immediate Action: Upgrade firmware for all affected Loytec devices to version 8.4.18.
Proactive Monitoring: Monitor device traffic for anomalous input strings directed at the OPC XML-DA server statistics interface. Audit web logs for signs of script injection attempts.
Compensating Controls: Use a Web Application Firewall (WAF) to filter malicious input patterns, and restrict network access to device management interfaces to authorized personnel only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Loytec device administrators should treat this vulnerability with high urgency. Given that the flaw allows for unauthenticated interaction, the risk of external exploitation is elevated. Applying the 8.4.18 firmware update is the only definitive way to neutralize this cross-site scripting risk.