CVE-2023-46381: Loytec Linx-212 Firmware

High severity, CVSS 8.2. EPSS: 7.4% chance of exploitation in the next 30 days.

LOYTEC LINX-151, LINX-212, LVIS-3ME12-A1, LIOB-586, LIOB-580 V2, LIOB-588, L-INX Configurator devices (all versions) lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

Affected products

  • Loytec Linx-212 Firmware: version 6.2.4 only
  • Loytec Liob-586 Firmware: version 6.2.3 only
  • Loytec Lvis-3me12-a1 Firmware: version 6.2.2 only

Published 2023-11-04. Last modified 2026-06-17.