Stack-Based Buffer Overflow in Loytec LIP-ME201C and Associated Products
CVE-2026-55728
3.8LOW
What is CVE-2026-55728?
A stack-based buffer overflow has been identified in the cmd_ipaddr_conflict function within Loytec's LIP-ME201C and various associated products, impacting versions up to 8.4.16 on the LINX-A64 platform. This vulnerability allows an attacker with superadmin privileges to cause a SUID-root process to abort or potentially escalate their privileges by sending an excessively long interface-name argument.
Affected Version(s)
L-DALI 0 <= 8.4.16
L-GATE 0 <= 8.4.16
L-INX 0 <= 8.4.16
References
CVSS V4
Score:
3.8
Severity:
LOW
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Daniel Hulliger, armasuisse CYD Campus
Damian Pfammatter, armasuisse CYD Campus
