GPU VulnDB

Database/Control plane, storage & DevOps

Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-bounds

CVE-2026-55732Control plane, storage & DevOpsCVE-2026-12496CVE-2026-12504CVE-2026-55731curated

Impact

An out-of-bounds read in BACnet packet parsing lets an unauthenticated attacker crash the main control process and reboot the device with a single malformed TimeSynchronization message - and BACnet TimeSynchronization is a broadcast service, so one packet can take out every Loytec device on the segment at once. Loytec controllers and gateways are the BACnet/LonWorks integration layer in a lot of European-designed and mixed-vendor datacenters, sitting between the IP supervisory network and the field bus that runs air handling. Rebooting them all simultaneously severs supervisory control of cooling for as long as the attacker keeps sending, which against 40-140 kW GPU racks is a straightforward path to thermal shutdown across a hall. The companion issues in the same disclosure set (unauthenticated stored XSS in the OPC XML-DA statistics page, a PAM misconfiguration allowing authentication as an unintended uid, and an SNMP agent loop-condition bug) mean the same devices also offer credential-theft and persistence paths, not just DoS.

Who can reach it

Unauthenticated, remote, over BACnet on the facility network - and via broadcast, so it does not even need to know device addresses. The SNMP and web issues are likewise reachable from anywhere on that segment. Anyone who can put a frame on the building VLAN can do this.

What to do

Firmware update from Loytec above 8.4.18 for the device family, plus LWEB-802 5.0.8+ for the management side. This is a per-device firmware flash across every gateway and controller, done by the controls integrator, with each device offline during the flash - a maintenance window on live cooling. Because a broadcast packet is the trigger, the compensating control has to actually block broadcast BACnet from untrusted hosts, which usually means putting the BACnet segment on its own VLAN with no untrusted hosts on it at all rather than trying to filter by address. Disable the SNMP agent and the OPC XML-DA interface if you are not using them.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.