Executive brief
A vulnerability in several Loytec building automation and control devices allows a user with high-level administrative privileges to reset the password of any other account, including critical service accounts. This could allow an administrator to take full control of the system or impersonate service accounts used for automated building operations. This risk impacts the integrity and availability of building management systems such as lighting, climate control, and security interfaces.
Technical details
An improper privilege management vulnerability (CWE-269) exists in the '/usr/bin/ltsudo' utility on Loytec devices running on the LINX-A64 platform. The 'set-passwd' subcommand fails to perform adequate authorization checks, allowing a user in the 'superadmin' group to reset the password of any LARM user, including the 'larmapp' service account, by providing user:password pairs via stdin. An attacker with local access and superadmin privileges can exploit this to impersonate service accounts or other users. The issue is addressed in firmware version 8.4.18.
Affected products
- Loytec LIP-ME201C through 8.4.16
- Loytec L-INX through 8.4.16
- Loytec L-GATE through 8.4.16
- Loytec L-ROC through 8.4.16
- Loytec L-IOB through 8.4.16
- Loytec L-DALI through 8.4.16
- Loytec L-VIS through 8.4.16
- Loytec L-PAD through 8.4.16
Timeline
- 2026-07-24: advisory: NVD publication date
- 2026-07-24: disclosed: Initial disclosure by Switzerland Government Common Vulnerability Program