Out-of-bounds Read in BACnet Packet Parsing
CVE:
CVE-2026-55732
Product: Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC
Severity: High 8.7
Published: 24.07.2026
Advisory:
Read the advisory
An out-of-bounds read (CWE-125) in the BACnet packet parsing routine bacdt_datetime_to_tod of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.18 (LINX-A64) allows an unauthenticated remote attacker to crash linx_a64.exe and ultimately reboot the device by sending a malformed BACnet TimeSynchronization or UTC-TimeSynchronization packet with an invalid month value. The same defect affects several further Loytec products.