Junglewise Threat Intelligence

CVE-2026-47116: LTSecurity LTK3500SF hard-coded credentials in authentication

CVE-2026-47116 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Executive brief

The LTSecurity LTK3500SF is a network-attached security appliance containing hard-coded passwords for privileged accounts stored in the device's shadow password file. An attacker can extract and crack these weak hashes using standard dictionary tools to obtain root-level access via Telnet or SSH, allowing full system compromise and control of the device.

Technical details

Hard-coded MD5-crypt hashes for root and guest accounts are embedded in /etc/shadow on the device; the hashes are weak (password "12345") and recoverable via dictionary attack. Exploitation requires network access to Telnet or SSH services (attack vector: network), but these services are not confirmed to start automatically, so a precondition is that SSH or Telnet is enabled or running. Successful credential recovery grants unauthenticated root-level OS access.

Affected products

  • LTSecurity LTK3500SF AC3F_V1.1.0_build191121 and earlier

Timeline

  • 2026-09-22: disclosed

References