Improper Privilege Management in /usr/bin/ltsudo
CVE:
CVE-2026-12502
Product: Loytec / L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD, LIP-ME20xC
Severity: High 8.4
Published: 24.07.2026
Advisory:
Read the advisory
Improper privilege management (CWE-269) in /usr/bin/ltsudo on Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 (LINX-A64) allows an attacker in the superadmin group to reset the password of any LARM user, including the larmapp service account, through the set-passwd subcommand.