Loytec LWEB-802 before 5.0.8 stores management credentials in the browser’s localStorage without adequate protection (CWE-200). An unauthenticated remote attacker can leak the stored credentials by luring a user into opening a crafted link.