CVE-2026-55729: Loytec Lweb-802

High severity, CVSS 7.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.

Affected products

  • Loytec Lweb-802: before 5.0.8 (fixed in 5.0.8)

Published 2026-07-24. Last modified 2026-07-27.