Executive brief
The LTSecurity LTK3500SF is a network-attached security appliance containing hard-coded passwords for privileged accounts stored in the device's shadow password file. An attacker can extract and crack these weak hashes using standard dictionary tools to obtain root-level access via Telnet or SSH, allowing full system compromise and control of the device.
Technical details
Hard-coded MD5-crypt hashes for root and guest accounts are embedded in /etc/shadow on the device; the hashes are weak (password "12345") and recoverable via dictionary attack. Exploitation requires network access to Telnet or SSH services (attack vector: network), but these services are not confirmed to start automatically, so a precondition is that SSH or Telnet is enabled or running. Successful credential recovery grants unauthenticated root-level OS access.
Affected products
- LTSecurity LTK3500SF AC3F_V1.1.0_build191121 and earlier
Timeline
- 2026-09-22: disclosed