CVE-2026-12504: CWE-287 Improper authentication in Loytec LIP-ME20xC
CVE-2026-12504 is a high-severity improper authentication vulnerability in the PAM configuration of Loytec LIP-ME20xC devices and related products up to version 8.4.16 on LINX-A64. It allows a local attacker to authenticate as the root user without a password by exploiting an /etc/passwd entry with an empty password field, resulting in root shell access.
AI Analysis
Technical Summary
This vulnerability (CWE-287) affects the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD products through version 8.4.16 on LINX-A64. A local attacker can bypass authentication and gain root privileges by leveraging an /etc/passwd entry that has an empty password field, effectively allowing passwordless root login. The CVSS 4.0 score is 8.4, indicating high severity. No patch or official remediation guidance is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation grants a local attacker root shell access without requiring a password, compromising system integrity and control. This can lead to full system compromise and unauthorized administrative actions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict local access to trusted users only and monitor for unauthorized access attempts. Avoid relying on the affected PAM configuration and consider alternative authentication mechanisms if feasible.
CVE-2026-12504: CWE-287 Improper authentication in Loytec LIP-ME20xC
Description
CVE-2026-12504 is a high-severity improper authentication vulnerability in the PAM configuration of Loytec LIP-ME20xC devices and related products up to version 8.4.16 on LINX-A64. It allows a local attacker to authenticate as the root user without a password by exploiting an /etc/passwd entry with an empty password field, resulting in root shell access.
CVSS v4.0
Score 8.4high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-287) affects the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD products through version 8.4.16 on LINX-A64. A local attacker can bypass authentication and gain root privileges by leveraging an /etc/passwd entry that has an empty password field, effectively allowing passwordless root login. The CVSS 4.0 score is 8.4, indicating high severity. No patch or official remediation guidance is currently provided by the vendor, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation grants a local attacker root shell access without requiring a password, compromising system integrity and control. This can lead to full system compromise and unauthorized administrative actions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict local access to trusted users only and monitor for unauthorized access attempts. Avoid relying on the affected PAM configuration and consider alternative authentication mechanisms if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NCSC.ch
- Date Reserved
- 2026-06-17T09:48:17.638Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6378c49c2644c7f8151c34
Added to database: 07/24/2026, 14:37:56 UTC
Last enriched: 07/31/2026, 15:19:10 UTC
Last updated: 09/07/2026, 10:52:06 UTC
Views: 76
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.