What is CVE-2026-12496?
This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the OPC XML-DA server statistics of various Loytec devices, including LIP-ME201C, L-INX, and L-GATE. An unauthenticated remote attacker can exploit this to execute arbitrary JavaScript in an administrator's browser, potentially leading to session hijacking. Affected users should apply the vendor's security patches immediately.
Azərbaycanca: Bu zəiflik Loytec cihazlarının OPC XML-DA server statistikasında saxlanılan XSS (Stored Cross-Site Scripting) qüsurudur. Təsirə məruz qalan cihazlara LIP-ME201C, L-INX, L-GATE və digər Loytec modelləri daxildir. İstifadəçilər istehsalçı tərəfindən təqdim olunan yamaqları tətbiq etməli və ya müvəqqəti olaraq təsirə məruz qalan interfeyslərə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Loytec
FAQ2
Which Loytec device models are affected by CVE-2026-12496?
LIP-ME201C, L-INX, L-GATE, and other Loytec models are affected by this vulnerability.
What should users do to protect against CVE-2026-12496?
They should apply the vendor's security patches immediately or temporarily restrict access to the affected interfaces.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.