Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update to LWEB-802 version 5.0.8.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link. | |
| Title | Loytec LWEB802: Exposure of Sensitive Information in browser localStorage | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-07-24T14:55:29.967Z
Reserved: 2026-06-17T09:48:05.268Z
Link: CVE-2026-55729
Updated: 2026-07-24T14:55:24.954Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses