CVE-2026-55730 Details
Description
Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.
A reflected cross-site scripting vulnerability has been identified in Loytec LWEB-802 versions prior to 5.0.8, across all platforms. This vulnerability allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of the victim's browser. The issue arises when a crafted link containing a malicious 'project' or 'mspParams' parameter is used, enabling the attacker to perform actions with the victim's privileges.
Users are advised to update to Loytec LWEB-802 version 5.0.8.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.loytec.com/support/product-security/advisories/8527-dibt-cve-20260601-0002-reflected-cross-site-scripting-xss-high | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Loytec LWEB-802 | < 5.0.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | New CVE Received | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
Volerion