Executive brief
Loytec building automation devices, including touch panels and lighting controllers, contain a security flaw in their authentication configuration. An attacker who already has limited access to the device can exploit this to gain full administrative (root) control without a password. This could allow an unauthorized user to disrupt building operations, modify system settings, or access sensitive data.
Technical details
The vulnerability exists in the Pluggable Authentication Module (PAM) configuration of several Loytec building automation products. The configuration utilizes 'pam_unix.so' with the 'nullok' option enabled. A local attacker with the ability to modify or append entries to the '/etc/passwd' file can create a new account with a UID of 0 and an empty password field. By then using the 'su' command, the attacker can authenticate as that user without providing a password, effectively obtaining a root shell. This issue affects multiple product lines on the LINX-A64 platform through firmware version 8.4.16. Users are advised to upgrade to firmware version 8.4.18.
Affected products
- Loytec LIP-ME201C through 8.4.16
- Loytec L-INX through 8.4.16
- Loytec L-GATE through 8.4.16
- Loytec L-ROC through 8.4.16
- Loytec L-IOB through 8.4.16
- Loytec L-DALI through 8.4.16
- Loytec L-VIS through 8.4.16
- Loytec L-PAD through 8.4.16
Timeline
- 2026-07-24: advisory: NVD and vendor advisory published