CVE-2026-55732 Details
Description
Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 on LINX-A64 allows an unauthenticated remote attacker to crash `linx_a64.exe` and ultimately reboot the device via a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same vulnerability affects multiple other Loytec products.
A vulnerability allowing out-of-bounds read has been identified in the BACnet packet parsing function 'bacdt_datetime_to_tod' across several Loytec products, including the LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD, all through version 8.4.18 on the LINX-A64 model. This vulnerability allows an unauthenticated remote attacker to crash the 'linx_a64.exe' process and ultimately reboot the device. The issue arises when a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet is sent with an invalid month value, causing an out-of-bounds read against the 'bacdt_days_till_month' lookup table. Although the 'linx_a64.exe' process is automatically restarted, repeated crashes can disrupt multiple core functions of the device, leading to a complete device reboot after several crashes.
Users are advised to upgrade to firmware version 8.4.20.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.loytec.com/support/product-security/advisories/8532-dibt-cve-20260608-0001-bacnet-crash-due-to-invalid-timesync-message-high | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Loytec LIP-ME201C | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-INX | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-GATE | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-ROC | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-IOB | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-DALI | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-VIS | <= 8.4.18 (semver) |
CPE
Remediation
| |
| Loytec L-PAD | <= 8.4.18 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | New CVE Received | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
Volerion