Description
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
Published: 2026-07-24
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper privilege management in the /usr/bin/ltsudo component of Loytec LINX-A64 firmware allows a user who is a member of the superadmin group to reset the password of any LARM user, including the critical larmapp service account. By resetting these passwords an attacker can assume the LARM service’s identity and execute commands on the device, effectively gaining full control of the system’s operating state.

Affected Systems

The flaw exists in firmware versions up to and including 8.4.16 for eight product lines – L-DALI, L-GATE, L-INX, L-IOB, L-PAD, L-ROC, L-VIS and LIP-ME20xC. An upgrade to firmware 8.4.18 or later resolves the vulnerability.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% indicates a low overall probability of exploitation at this time. The attack requires local membership in the superadmin group and can be carried out via the set-passwd subcommand within ltsudo, providing the attacker with the ability to reset any LARM account password. The vulnerability is not listed in CISA’s KEV catalog, but the potential for device takeover warrants prompt action.

Generated by OpenCVE AI on August 3, 2026 at 20:17 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 8.4.18.


OpenCVE Recommended Actions

  • Upgrade all affected devices to firmware version 8.4.18 or later
  • Restrict superadmin group membership to trusted administrators only
  • If feasible, disable the set‑passwd subcommand or remove ltsudo to eliminate the password‑reset path
  • Monitor LARM account password changes for anomalous activity

Generated by OpenCVE AI on August 3, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc
Vendors & Products Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
Title Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T14:58:22.991Z

Reserved: 2026-06-17T09:48:08.859Z

Link: CVE-2026-12502

cve-icon Vulnrichment

Updated: 2026-07-24T14:58:14.685Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:17:10.860

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-12502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management