ZeroHour

Vulnerabilities

17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-46389
+3 in the same advisory: …46387 …46386 …46388
LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file.

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

NVD description · AI analysis pending
7.52%
  • loytec linx-212 firmware
  • loytec linx-151 firmware
CVE-2023-46384
+2 in the same advisory: …46383 …46385
LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions.

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

NVD description · AI analysis pending
7.52%
  • loytec l-inx configurator
CVE-2023-46381
+2 in the same advisory: …46382 …46380
LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled ve

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

NVD description · AI analysis pending
8.2
group max
7%
  • loytec linx-212 firmware
  • loytec lvis-3me12-a1 firmware
  • loytec liob-586 firmware
CVE-2018-14916
+2 in the same advisory: …14918 …14919
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

NVD description · AI analysis pending
9.1
group max
17% PoC ×3
  • loytec lgate-902 firmware
CVE-2017-13996
+3 in the same advisory: …13992 …13998 …13994
A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0.

A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute arbitrary code.

NVD description · AI analysis pending
8.8
group max
3%
  • loytec lvis-3me firmware