Impact
A stack-based buffer overflow (CWE‑121) exists in the cmd_ipaddr_conflict routine of the /usr/bin/ltsudo binary on Loytec devices. The flaw allows an attacker who is a member of the protected superadmin group to provide an overly long interface‑name argument, causing an overflow that can abort the SUID‑root process or, at a minimum, elevate privileges. The vulnerability gives an attacker the ability to execute commands with root privileges, thereby compromising system integrity and confidentiality.
Affected Systems
Affected vendors include Loytec, with product lines L‑DALI, L‑GATE, L‑INX, L‑IOB, L‑PAD, L‑ROC, L‑VIS, and LIP‑ME20xC. The issue exists in firmware versions up through 8.4.16 on the LINX‑A64 platform. The recommended fix is to upgrade to firmware version 8.4.18.
Risk and Exploitability
The CVSS score of 3.8 indicates low overall severity, and an EPSS score of less than 1% suggests a very small likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing its threat visibility. Exploitation requires local access to the device and membership in the superadmin group, meaning the attack vector is likely from within the network or from an authenticated user already logged into the device. Attackers would trigger the overflow by sending a crafted, excessively long interface name during IP address conflict processing. Because the attack affects privileged processes, it can lead to unauthorized root access, but the low prevalence and required access level keep the overall risk comparatively modest.
OpenCVE Enrichment