Impact
LTSecurity LTK3500SF firmware contains hard‑coded root and guest account passwords stored as reversible hashes in /etc/shadow. An attacker who can read the file can recover these credentials with a dictionary attack. Once obtained, they can authenticate over Telnet or SSH and gain full root level access to the device’s operating system. The weakness falls under CWE‑798, a credential exposure flaw that directly compromises confidentiality, integrity, and availability.
Affected Systems
The affected product is the LTSecurity LTK3500SF network gateway. No specific firmware version range is listed; the vulnerability appears to be present in all builds that retain the hard‑coded credentials. Users should verify which firmware revision their device is running against vendor documentation.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. Because the credentials are hard‑coded, an attacker only needs network access to the Telnet or SSH service, making exploitation straightforward for anyone who can reach the device. The EPSS score is not reported, and the flaw is not yet listed in the CISA KEV catalog, but the high CVSS and direct authentication vector imply a high risk. Attackers could gain unlimited control over the device, potentially affecting connected network infrastructure.
OpenCVE Enrichment