VULNERABILITY INTELLIGENCE

CVE-2026-55730

CVSS score8.7 HIGH
EPSS probability0.61%
CISA KEVNot currently listed
Published2026-07-24
Last modified2026-07-27
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser and perform actions with the victim's privileges via a crafted link containing a malicious `project` or `mspParams` parameter.

Weakness classification

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-116: Improper Encoding or Escaping of Output

Primary references