High severity8.2NVD Advisory· Published Nov 4, 2023· Updated Jun 17, 2026
CVE-2023-46381
CVE-2023-46381
Description
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- cpe:2.3:o:loytec:linx-212_firmware:6.2.4:*:*:*:*:*:*:*
- cpe:2.3:o:loytec:liob-586_firmware:6.2.3:*:*:*:*:*:*:*
- cpe:2.3:o:loytec:lvis-3me12-a1_firmware:6.2.2:*:*:*:*:*:*:*
- LOYTEC/LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configuratordescription
- Range: all versions
- Range: all versions
- Range: all versions
Patches
Vulnerability mechanics
References
5- packetstormsecurity.com/files/175646/LOYTEC-Electronics-Insecure-Transit-Insecure-Permissions-Unauthenticated-Access.htmlnvdThird Party Advisory
- seclists.org/fulldisclosure/2023/Nov/0nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2023/Nov/0nvd
- www.cisa.gov/news-events/ics-advisories/icsa-24-247-01nvd
- www.txone.com/blog/ten-unpatched-vulnerabilities-in-building-automation-products-identified-by-txone-networks/nvd
News mentions
0No linked articles in our index yet.