What is CVE-2026-12504?
This vulnerability allows a local attacker to authenticate as root (uid=0) without a password due to improper authentication in the PAM configuration of Loytec devices. By exploiting a special entry in /etc/passwd, an attacker can obtain a root shell. Affected devices running firmware through 8.4.16 should be updated.
Azərbaycanca: Bu boşluq Loytec cihazlarının PAM konfiqurasiyasında CWE-287 (zəif autentifikasiya) səbəbindən yerli hücumçuya şifrəsiz uid=0 (root) ilə autentifikasiya etməyə imkan verir. /etc/passwd faylındakı xüsusi giriş vasitəsilə root shell əldə oluna bilir. Təsirə məruz qalan cihazlar üçün 8.4.16 və daha əvvəlki versiyalar yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Does exploiting CVE-2026-12504 require initial access to the system?
Yes, this vulnerability allows a local attacker to authenticate as root without a password.
Which Loytec firmware versions are affected by CVE-2026-12504?
Devices running firmware through 8.4.16 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.