🔐 CVE Alert

CVE-2026-12502

UNKNOWN 0.0

Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.

CWE CWE-269
Vendor loytec
Product lip-me20xc
Published Jul 24, 2026
Last Updated Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for loytec lip-me20xc

Be the first to know when new unknown vulnerabilities affecting loytec lip-me20xc are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Loytec / LIP-ME20xC
0 ≤ 8.4.16
Loytec / L-INX
0 ≤ 8.4.16
Loytec / L-GATE
0 ≤ 8.4.16
Loytec / L-ROC
0 ≤ 8.4.16
Loytec / L-IOB
0 ≤ 8.4.16
Loytec / L-DALI
0 ≤ 8.4.16
Loytec / L-VIS
0 ≤ 8.4.16
Loytec / L-PAD
0 ≤ 8.4.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
loytec.com: https://www.loytec.com/support/product-security/advisories/8519-dibt-cve-20260526-0001-unrestricted-service-account-password-reset-high

Credits

Daniel Hulliger, armasuisse CYD Campus Damian Pfammatter, armasuisse CYD Campus