SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12504

HIGH · CVSS 8.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The vulnerability exists in the PAM configuration of various Loytec devices, allowing local attackers to gain unauthorized root access by authenticating as the uid=0 account without a password. This could lead to complete system compromise, enabling attackers to execute arbitrary commands with elevated privileges. Organizations using affected Loytec products should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-12504
Severity
HIGH
CVSS
8.4
EPSS
0.13%

Original NVD Description

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a local attacker to authenticate as a uid=0 account without a password and obtain a root shell via an `/etc/passwd` entry with an empty password field.