Description
Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long interface-name argument.
Published: 2026-07-24
Score: 3.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow (CWE‑121) exists in the cmd_ipaddr_conflict routine of the /usr/bin/ltsudo binary on Loytec devices. The flaw allows an attacker who is a member of the protected superadmin group to provide an overly long interface‑name argument, causing an overflow that can abort the SUID‑root process or, at a minimum, elevate privileges. The vulnerability gives an attacker the ability to execute commands with root privileges, thereby compromising system integrity and confidentiality.

Affected Systems

Affected vendors include Loytec, with product lines L‑DALI, L‑GATE, L‑INX, L‑IOB, L‑PAD, L‑ROC, L‑VIS, and LIP‑ME20xC. The issue exists in firmware versions up through 8.4.16 on the LINX‑A64 platform. The recommended fix is to upgrade to firmware version 8.4.18.

Risk and Exploitability

The CVSS score of 3.8 indicates low overall severity, and an EPSS score of less than 1% suggests a very small likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further reducing its threat visibility. Exploitation requires local access to the device and membership in the superadmin group, meaning the attack vector is likely from within the network or from an authenticated user already logged into the device. Attackers would trigger the overflow by sending a crafted, excessively long interface name during IP address conflict processing. Because the attack affects privileged processes, it can lead to unauthorized root access, but the low prevalence and required access level keep the overall risk comparatively modest.

Generated by OpenCVE AI on August 3, 2026 at 20:16 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 8.4.18.


OpenCVE Recommended Actions

  • Upgrade the firmware to version 8.4.18 or later, which removes the vulnerable cmd_ipaddr_conflict routine.
  • Prevent regular users from being added to the superadmin group or review existing group memberships, ensuring only trusted personnel have elevated privileges.
  • Restrict or audit write access to the /usr/bin/ltsudo binary and its configuration files to reduce the likelihood of privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc
Vendors & Products Loytec
Loytec l-dali
Loytec l-gate
Loytec l-inx
Loytec l-iob
Loytec l-pad
Loytec l-roc
Loytec l-vis
Loytec lip-me20xc

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long interface-name argument.
Title Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 3.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-07-24T14:56:40.020Z

Reserved: 2026-06-17T09:48:05.267Z

Link: CVE-2026-55728

cve-icon Vulnrichment

Updated: 2026-07-24T14:55:56.965Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T15:18:30.950

Modified: 2026-07-27T20:32:11.620

Link: CVE-2026-55728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow