Executive brief
A security vulnerability exists in several Loytec building automation and control devices, including L-INX and L-GATE servers. An authorized user with high-level administrative access could cause the system to crash or potentially gain even higher system-level privileges by providing an improperly formatted network interface name. This could lead to service disruptions or unauthorized control over the device's operating system.
Technical details
A stack-based buffer overflow (CWE-121) exists in the 'cmd_ipaddr_conflict' function within the '/usr/bin/ltsudo' SUID-root binary. The vulnerability is caused by the use of 'strcpy' to copy a user-supplied interface-name argument into a fixed 20-byte stack buffer without length validation. An attacker with 'superadmin' group privileges can exploit this locally to trigger a process abort or potentially achieve arbitrary code execution with root privileges. The issue affects multiple Loytec product lines on the LINX-A64 platform with firmware versions up to 8.4.16. A fix is available in firmware version 8.4.18.
Affected products
- Loytec LIP-ME201C through 8.4.16
- Loytec L-INX through 8.4.16
- Loytec L-GATE through 8.4.16
- Loytec L-ROC through 8.4.16
- Loytec L-IOB through 8.4.16
- Loytec L-DALI through 8.4.16
- Loytec L-VIS through 8.4.16
- Loytec L-PAD through 8.4.16
Timeline
- 2026-07-24: advisory
- 2026-07-24: disclosed
- 2026-07-24: patched: Fixed in firmware 8.4.18