loytec CVE Vulnerabilities & Metrics

Focus on loytec vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About loytec Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with loytec. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total loytec CVEs: 18
Earliest CVE date: 21 Dec 2015, 11:59 UTC
Latest CVE date: 30 Nov 2023, 23:15 UTC

Latest CVE reference: CVE-2023-46389

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical loytec CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.06

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 10
4.0-6.9 5
7.0-8.9 1
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS loytec CVEs

These are the five CVEs with the highest CVSS scores for loytec, sorted by severity first and recency.

All CVEs for loytec

CVE-2023-46389 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.

CVE-2023-46388 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via dpal_config.zml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-46387 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Incorrect Access Control via dpal_config.zml file. This vulnerability allows remote attackers to disclose sensitive information on Loytec device data point configuration.

CVE-2023-46386 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX-212 and LINX-151 devices (all versions) are vulnerable to Insecure Permissions via registry.xml file. This vulnerability allows remote attackers to disclose smtp client account credentials and bypass email authentication.

CVE-2023-46385 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration.

CVE-2023-46384 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device.

CVE-2023-46383 loytec vulnerability CVSS: 0 30 Nov 2023, 23:15 UTC

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration.

CVE-2023-46382 loytec vulnerability CVSS: 0 04 Nov 2023, 23:15 UTC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) use cleartext HTTP for login.

CVE-2023-46381 loytec vulnerability CVSS: 0 04 Nov 2023, 23:15 UTC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

CVE-2023-46380 loytec vulnerability CVSS: 0 04 Nov 2023, 23:15 UTC

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) send password-change requests via cleartext HTTP.

CVE-2018-14918 loytec vulnerability CVSS: 7.8 28 Jun 2019, 18:15 UTC

LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.

CVE-2018-14916 loytec vulnerability CVSS: 9.4 28 Jun 2019, 18:15 UTC

LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

CVE-2018-14919 loytec vulnerability CVSS: 4.3 28 Jun 2019, 17:15 UTC

LOYTEC LGATE-902 6.3.2 devices allow XSS.

CVE-2017-13998 loytec vulnerability CVSS: 6.0 05 Oct 2017, 21:29 UTC

An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficiently protect sensitive information from unauthorized access.

CVE-2017-13996 loytec vulnerability CVSS: 6.5 05 Oct 2017, 21:29 UTC

A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute arbitrary code.

CVE-2017-13994 loytec vulnerability CVSS: 4.3 05 Oct 2017, 21:29 UTC

A Cross-site Scripting issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web interface lacks proper web request validation, which could allow XSS attacks to occur if an authenticated user of the web interface is tricked into clicking a malicious link.

CVE-2017-13992 loytec vulnerability CVSS: 6.8 05 Oct 2017, 21:29 UTC

An Insufficient Entropy issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not utilize sufficiently random number generation for the web interface authentication mechanism, which could allow remote code execution.

CVE-2015-7906 loytec vulnerability CVSS: 10.0 21 Dec 2015, 11:59 UTC

LOYTEC LIP-3ECTB 6.0.1, LINX-100, LVIS-3E100, and LIP-ME201 devices allow remote attackers to read a password-hash backup file via unspecified vectors.