CVE-2026-55731
Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to cause persistent denial of service (CPU exhaustion) via a crafted SNMP GETNEXT request with a large OID component.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.32%
- CWE
- CWE-606
- Published
- 2026-07-24
- Last modified
- 2026-07-24
Affected products
- Loytec LIP-ME20xC
- Loytec L-INX
- Loytec L-GATE
- Loytec L-ROC
- Loytec L-IOB
- Loytec L-DALI
- Loytec L-VIS
- Loytec L-PAD
Weakness type
Related vulnerabilities
- CVE-2026-85730 — smol-toml: Denial of Service via malformed TOML documents
- CVE-2026-13761 — Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
- CVE-2026-16599 — Denial of Service in GNU wget
- CVE-2026-62901 — .NET Denial of Service Vulnerability
- CVE-2026-71439 — Mermaid radar diagrams are vulnerable to DoS
- CVE-2026-20301 — Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
- CVE-2026-67554 — Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
- CVE-2026-68077 — Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service