Back

HIGH

Loytec LWEB802: Exposure of Sensitive Information in browser localStorage

Published Jul 24, 2026

Description

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to leak stored management credentials via a crafted link.

Affected products

Remediation

Vendor solution

Update to LWEB-802 version 5.0.8.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner NCSC.ch
Published Jul 24, 2026
Updated Jul 24, 2026
Reserved Jun 17, 2026
CISA Vulnrichment
Updated Jul 24, 2026
NVD
Status Deferred
Modified Jul 27, 2026
Red Hat
Severity n/a
Public date n/a