Impact
Improper privilege management in the /usr/bin/ltsudo component of Loytec LINX-A64 firmware allows a user who is a member of the superadmin group to reset the password of any LARM user, including the critical larmapp service account. By resetting these passwords an attacker can assume the LARM service’s identity and execute commands on the device, effectively gaining full control of the system’s operating state.
Affected Systems
The flaw exists in firmware versions up to and including 8.4.16 for eight product lines – L-DALI, L-GATE, L-INX, L-IOB, L-PAD, L-ROC, L-VIS and LIP-ME20xC. An upgrade to firmware 8.4.18 or later resolves the vulnerability.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, while the EPSS score of less than 1% indicates a low overall probability of exploitation at this time. The attack requires local membership in the superadmin group and can be carried out via the set-passwd subcommand within ltsudo, providing the attacker with the ability to reset any LARM account password. The vulnerability is not listed in CISA’s KEV catalog, but the potential for device takeover warrants prompt action.
OpenCVE Enrichment