Loytec specializes in embedded building-automation and gateway products, particularly its LINX line of controllers and firmware, which occupy a specialized but persistent niche in networked infrastructure. Its vulnerability profile is anchored in a recurring pattern of credential and data-handling weaknesses—cleartext transmission and storage of sensitive information, path traversal, and cross-site scripting—typical of legacy embedded systems where security hardening lags feature deployment, and public exploit code frequently becomes available for disclosed flaws. Defenders should prioritize inventory and network isolation of these gateway devices, since their role in building-management networks can provide lateral access; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loytec over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14916CRITICAL LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. | Jun 28, 2019 | 9.1 | 49 | NO | YES |
CVE-2018-14918HIGH LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. | Jun 28, 2019 | 7.5 | 44 | NO | YES |
CVE-2015-7906HIGH LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors. | Dec 21, 2015 | 10.0 | 31 | NO | NO |
CVE-2023-46381HIGH LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 vi | Nov 4, 2023 | 8.2 | 27 | NO | NO |
CVE-2017-13996HIGH A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative | Oct 5, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-13992HIGH An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interfac | Oct 5, 2017 | 8.1 | 25 | NO | NO |
CVE-2023-46389HIGH LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to | Nov 30, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-46387HIGH LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers | Nov 30, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-46382HIGH LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login. | Nov 4, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-46380HIGH LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP. | Nov 4, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loytec.
Media articles that mention a CVE ID that affects a product developed by Loytec — matched by CVE ID, not by vendor name.