What is CVE-2026-55728?
CVE-2026-55728 is a stack-based buffer overflow vulnerability in the `ltsudo` tool on Loytec devices, specifically in the `cmd_ipaddr_conflict` function. It allows a `superadmin`-group attacker to crash the SUID-root process or potentially escalate privileges. Affected devices should be updated to version 8.4.16 or later.
Azərbaycanca: CVE-2026-55728, Loytec cihazlarının `ltsudo` alətində olan stack-based buffer overflow zəifliyidir. Bu boşluq `cmd_ipaddr_conflict` funksiyasında yaranır və `superadmin` qrupundakı şəxsə SUID-root prosesini çökdürməyə və ya potensial olaraq imtiyazları yüksəltməyə imkan verir. Təsirə məruz qalan cihazları 8.4.16 versiyasına qədər yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What type of vulnerability is CVE-2026-55728 and where is it located?
CVE-2026-55728 is a stack-based buffer overflow vulnerability located in the `cmd_ipaddr_conflict` function of the `ltsudo` tool on Loytec devices.
What access level does an attacker need to exploit CVE-2026-55728 and what is the recommended solution?
The attacker must belong to the `superadmin` group. To address this vulnerability, affected devices should be updated to version 8.4.16 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.