Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to firmware 8.4.18.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Loytec
Loytec l-dali Loytec l-gate Loytec l-inx Loytec l-iob Loytec l-pad Loytec l-roc Loytec l-vis Loytec lip-me20xc |
|
| Vendors & Products |
Loytec
Loytec l-dali Loytec l-gate Loytec l-inx Loytec l-iob Loytec l-pad Loytec l-roc Loytec l-vis Loytec lip-me20xc |
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`. | |
| Title | Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-07-24T14:57:47.202Z
Reserved: 2026-06-17T09:48:11.206Z
Link: CVE-2026-12503
Updated: 2026-07-24T14:57:41.733Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T15:23:28Z