What is CVE-2026-12502?
This vulnerability stems from improper privilege management in `/usr/bin/ltsudo` across various Loytec devices, allowing an attacker in the `superadmin` group to reset the password of any LARM user, including service accounts. It affects models such as LIP-ME201C and L-INX through version 8.4.16 on LINX-A64, enabling unauthorized account access. Mitigation involves updating affected devices and strictly controlling `superadmin` group membership.
Azərbaycanca: Bu boşluq Loytec-in LIP-ME201C, L-INX kimi qurğularında `/usr/bin/ltsudo` faylında zəif icazə idarəetməsindən qaynaqlanır. `superadmin` qrupuna daxil olan təcavüzkar, xidmət hesabı da daxil olmaqla istənilən LARM istifadəçisinin şifrəsini sıfırlaya bilər. Qurğuları ən son versiyaya yeniləmək və `superadmin` qrup üzvlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-269; shared vendor: Loytec
FAQ2
What group must an attacker be part of to exploit CVE-2026-12502?
The attacker must be part of the `superadmin` group to exploit this vulnerability.
Which file's improper privilege management causes this vulnerability?
The vulnerability stems from improper privilege management in the `/usr/bin/ltsudo` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.