What is CVE-2026-55732?
This Out-of-bounds Read vulnerability in Loytec devices' BACnet packet parsing allows an unauthenticated remote attacker to crash the main service process and force a device reboot via a malformed BACnet packet. Affected devices should be updated to the latest firmware provided by the vendor.
Azərbaycanca: Loytec cihazlarında BACnet paket analizində aşkar edilmiş bu boşluq uzaqdan autentifikasiya olunmamış hücumçuya xüsusi hazırlanmış BACnet paketi göndərərək xidmət prosesini çökdürməyə və cihazın yenidən başlamasına səbəb ola bilər. Zərərçəkən cihazlar üçün istehsalçı tərəfindən buraxılmış proqram təminatı yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Is authentication required to exploit CVE-2026-55732?
No, this vulnerability allows a remote unauthenticated attacker, meaning the attacker can send a malformed BACnet packet without providing any credentials.
What is the impact of successfully exploiting CVE-2026-55732?
Successful exploitation can crash the main service process and force the device to reboot.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.