Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to firmware version 8.4.18.
Workaround
No workaround given by the vendor.
References
History
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field. | |
| Title | Loytec LINX firmware: Improper Authentication in PAM configuration | |
| Weaknesses | CWE-287 CWE-521 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-07-24T14:57:20.563Z
Reserved: 2026-06-17T09:48:17.638Z
Link: CVE-2026-12504
Updated: 2026-07-24T14:57:15.943Z
No data.
No data.
OpenCVE Enrichment
No data.