Description
LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can use the recovered credentials to authenticate via Telnet or SSH and obtain full root-level access to the operating system.
Published: 2026-09-22
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Root-level Access
Action: Patch
AI Analysis

Impact

LTSecurity LTK3500SF firmware contains hard‑coded root and guest account passwords stored as reversible hashes in /etc/shadow. An attacker who can read the file can recover these credentials with a dictionary attack. Once obtained, they can authenticate over Telnet or SSH and gain full root level access to the device’s operating system. The weakness falls under CWE‑798, a credential exposure flaw that directly compromises confidentiality, integrity, and availability.

Affected Systems

The affected product is the LTSecurity LTK3500SF network gateway. No specific firmware version range is listed; the vulnerability appears to be present in all builds that retain the hard‑coded credentials. Users should verify which firmware revision their device is running against vendor documentation.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. Because the credentials are hard‑coded, an attacker only needs network access to the Telnet or SSH service, making exploitation straightforward for anyone who can reach the device. The EPSS score is not reported, and the flaw is not yet listed in the CISA KEV catalog, but the high CVSS and direct authentication vector imply a high risk. Attackers could gain unlimited control over the device, potentially affecting connected network infrastructure.

Generated by OpenCVE AI on September 22, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Flash the latest LTSecurity firmware that eliminates hard‑coded credentials.
  • Disable Telnet and use only SSH with key‑based authentication, ensuring that passwords are required to be strong and unique.
  • Limit network exposure by placing the device behind a firewall and restricting inbound connections to trusted management IP addresses.

Generated by OpenCVE AI on September 22, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can use the recovered credentials to authenticate via Telnet or SSH and obtain full root-level access to the operating system.
Title LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T19:19:49.449Z

Reserved: 2026-05-18T19:22:26.749Z

Link: CVE-2026-47116

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T20:17:03.583

Modified: 2026-09-22T20:17:03.583

Link: CVE-2026-47116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:45:16Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials