ICSA-16-231-01-0
·
Published 2025-06-25
·
View on CISA ICS-CERT ↗
Locus Energy LGate Command Injection Vulnerability
CVSS 8.6
HIGH
CVEs (1)
Remediations
- Locus Energy has produced the following procedure to update LGate: 1. Cycle power to the LGate. This might require tripping one or more AC or DC breakers. 2. Power up the LGate and wait 5 minutes. 3. Use the web page on the LGate within the first half hour after power up to verify its firmware version. 3a. If connected to the local network, find the IP assigned to the LGate. Navigate to this IP using the browser on a computer also connected to the same subnet as the LGate. 3b. If the LGate is not connected to the local network, plug the Ethernet cable from the LGate into the computer. Wait until the computer settles into an AutoIP address in the 169.254.X.X range. Then use the IP 169.254.12.13 for the LGate. Use this IP in a browser to pull up the LGate web page. 4. The web page will display the model type, IP address, firmware version of the LGate (labeled as APP), and MAC address. Here is an example. In the picture below, the LGate (00:1E:C0:89:15:6E) is running 1.05C_EM3. 5. Verify that the firmware version is 1.05H_EM3 or above. 6. If the firmware version is less than 1.05H, send an email to ([email protected]) with the subject line: URGENT FW UPDATE REQUEST: MAC: <insert MAC address here> TO 1.05H or higher FW. 7. Locus Energy support will attempt to remotely update the firmware on the LGate and confirm via email. If they encounter any difficulty in updating the LGate, Locus Energy will contact the user to arrange alternate methods to update or replace the LGate. 8. If support confirms that the unit was updated to Version 1.05H or later, the user may repeat the above procedure (Steps 1-5) to verify this.
Affected Vendors
Locus Energy
Affected Products (6)
Locus Energy
·
LGate
<1.05H
Locus Energy
·
LGate 50
<1.05H
Locus Energy
·
LGate 100
<1.05H
Locus Energy
·
LGate 101
<1.05H
Locus Energy
·
LGate 120
<1.05H
Locus Energy
·
LGate 320
<1.05H
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more