CVE-2026-12502: CWE-269 Improper privilege management in Loytec LIP-ME20xC
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
AI Analysis
Technical Summary
This vulnerability involves improper privilege management (CWE-269) in the /usr/bin/ltsudo binary on Loytec LIP-ME20xC and associated products running LINX-A64 up to version 8.4.16. An attacker who is already a member of the superadmin group can exploit the set-passwd subcommand to reset passwords of any LARM user account, including the larmapp service account. This could allow unauthorized privilege escalation or disruption of service. The vulnerability is documented with CVSS 4.0 vector AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, indicating local attack with high impact on confidentiality, integrity, and availability. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with superadmin group privileges can reset passwords for any LARM user account, including critical service accounts. This could lead to unauthorized access or control over system components that rely on these accounts, potentially compromising system integrity and availability. The vulnerability requires local access with high privileges but results in high impact on confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict superadmin group membership to trusted users only and monitor for unauthorized use of the set-passwd subcommand. No official fix or temporary workaround has been published by the vendor at this time.
CVE-2026-12502: CWE-269 Improper privilege management in Loytec LIP-ME20xC
Description
Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to reset the password of any LARM user (including the `larmapp` service account) via the `set-passwd` subcommand.
CVSS v4.0
Score 8.4high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves improper privilege management (CWE-269) in the /usr/bin/ltsudo binary on Loytec LIP-ME20xC and associated products running LINX-A64 up to version 8.4.16. An attacker who is already a member of the superadmin group can exploit the set-passwd subcommand to reset passwords of any LARM user account, including the larmapp service account. This could allow unauthorized privilege escalation or disruption of service. The vulnerability is documented with CVSS 4.0 vector AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N, indicating local attack with high impact on confidentiality, integrity, and availability. No vendor advisory or patch information is currently available.
Potential Impact
An attacker with superadmin group privileges can reset passwords for any LARM user account, including critical service accounts. This could lead to unauthorized access or control over system components that rely on these accounts, potentially compromising system integrity and availability. The vulnerability requires local access with high privileges but results in high impact on confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict superadmin group membership to trusted users only and monitor for unauthorized use of the set-passwd subcommand. No official fix or temporary workaround has been published by the vendor at this time.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NCSC.ch
- Date Reserved
- 2026-06-17T09:48:08.859Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6378c49c2644c7f8151c2e
Added to database: 07/24/2026, 14:37:56 UTC
Last enriched: 07/24/2026, 14:52:44 UTC
Last updated: 07/25/2026, 01:43:26 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.