Impact
Improper Link Resolution (CWE-59) in /usr/bin/larm_starter allows an authenticated larmapp user to create a malicious symlink at /etc/lighttpd/ssl/server.pem. When the application follows the symlink, it writes to /etc/passwd, effectively giving the attacker root privileges.
Affected Systems
The affected devices are Loytec LINX system firmware for L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD running firmware versions up to and including 8.4.16 on the LINX-A64 platform.
Risk and Exploitability
The CVSS score of 9.2 indicates critical severity, while the EPSS score of less than 1% suggests low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; it requires an attacker to be authenticated as larmapp and to have permission to create the symlink in /etc/lighttpd/ssl.
OpenCVE Enrichment