Stack-Based Buffer Overflow in Loytec LIP-ME201C and Associated Products
CVE-2026-55728

3.8LOW

Key Information:

Vendor

Loytec

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-55728?

A stack-based buffer overflow has been identified in the cmd_ipaddr_conflict function within Loytec's LIP-ME201C and various associated products, impacting versions up to 8.4.16 on the LINX-A64 platform. This vulnerability allows an attacker with superadmin privileges to cause a SUID-root process to abort or potentially escalate their privileges by sending an excessively long interface-name argument.

Affected Version(s)

L-DALI 0 <= 8.4.16

L-GATE 0 <= 8.4.16

L-INX 0 <= 8.4.16

References

CVSS V4

Score:
3.8
Severity:
LOW
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Hulliger, armasuisse CYD Campus
Damian Pfammatter, armasuisse CYD Campus
.