Improper privilege management (CWE-269) in /usr/bin/ltsudo on Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) allows an attacker in the superadmin group to reset the password of any LARM user, including the larmapp service account, through the set-passwd subcommand.