CVE-2026-55728: CWE-121 Stack-based buffer overflow in Loytec LIP-ME20xC
A stack-based buffer overflow vulnerability (CWE-121) exists in the /usr/bin/ltsudo cmd_ipaddr_conflict component of Loytec LIP-ME20xC devices running LINX-A64 through version 8.4.16. This flaw can be triggered by a user in the superadmin group by supplying an overly long interface-name argument, potentially causing a SUID-root process to abort or allowing privilege escalation. The vulnerability has a low CVSS 4.0 base score of 3.8 and requires local low-complexity access with partial privileges. No official patch or remediation guidance is currently available from the vendor.
AI Analysis
Technical Summary
CVE-2026-55728 is a stack-based buffer overflow vulnerability in the cmd_ipaddr_conflict function of /usr/bin/ltsudo on Loytec LIP-ME20xC devices running LINX-A64 firmware up to version 8.4.16. A local attacker with superadmin group privileges can exploit this by providing an excessively long interface-name argument, which may cause the SUID-root process to abort or potentially lead to privilege escalation. The vulnerability is classified under CWE-121 and has a CVSS 4.0 score of 3.8, indicating low severity. There is no vendor advisory or patch available at this time, and no known exploits have been reported in the wild.
Potential Impact
Exploitation of this vulnerability can cause the SUID-root process to abort, resulting in denial of service for that process. Additionally, there is potential for privilege escalation if the buffer overflow is successfully leveraged, allowing a local superadmin user to gain higher privileges. The impact is limited by the requirement for local superadmin group access and the low complexity of the attack vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict superadmin group membership to trusted users only and monitor for any unusual activity involving the /usr/bin/ltsudo process. Avoid supplying overly long interface-name arguments to the vulnerable command.
CVE-2026-55728: CWE-121 Stack-based buffer overflow in Loytec LIP-ME20xC
Description
A stack-based buffer overflow vulnerability (CWE-121) exists in the /usr/bin/ltsudo cmd_ipaddr_conflict component of Loytec LIP-ME20xC devices running LINX-A64 through version 8.4.16. This flaw can be triggered by a user in the superadmin group by supplying an overly long interface-name argument, potentially causing a SUID-root process to abort or allowing privilege escalation. The vulnerability has a low CVSS 4.0 base score of 3.8 and requires local low-complexity access with partial privileges. No official patch or remediation guidance is currently available from the vendor.
CVSS v4.0
Score 3.8low
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55728 is a stack-based buffer overflow vulnerability in the cmd_ipaddr_conflict function of /usr/bin/ltsudo on Loytec LIP-ME20xC devices running LINX-A64 firmware up to version 8.4.16. A local attacker with superadmin group privileges can exploit this by providing an excessively long interface-name argument, which may cause the SUID-root process to abort or potentially lead to privilege escalation. The vulnerability is classified under CWE-121 and has a CVSS 4.0 score of 3.8, indicating low severity. There is no vendor advisory or patch available at this time, and no known exploits have been reported in the wild.
Potential Impact
Exploitation of this vulnerability can cause the SUID-root process to abort, resulting in denial of service for that process. Additionally, there is potential for privilege escalation if the buffer overflow is successfully leveraged, allowing a local superadmin user to gain higher privileges. The impact is limited by the requirement for local superadmin group access and the low complexity of the attack vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict superadmin group membership to trusted users only and monitor for any unusual activity involving the /usr/bin/ltsudo process. Avoid supplying overly long interface-name arguments to the vulnerable command.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NCSC.ch
- Date Reserved
- 2026-06-17T09:48:05.267Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6378c49c2644c7f8151c3b
Added to database: 07/24/2026, 14:37:56 UTC
Last enriched: 07/31/2026, 15:20:41 UTC
Last updated: 09/07/2026, 10:52:09 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.