An out-of-bounds read (CWE-125) in the BACnet packet parsing routine bacdt_datetime_to_tod of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 (LINX-A64) allows an unauthenticated remote attacker to crash linx_a64.exe and ultimately reboot the device by sending a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same defect affects several further Loytec products.