CVE-2026-55728 Details
Description
Stack-based Buffer Overflow (CWE-121) in `/usr/bin/ltsudo` `cmd_ipaddr_conflict` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows a `superadmin`-group attacker to trigger a SUID-root process abort or potentially elevate privileges via an overly long interface-name argument.
A stack-based buffer overflow vulnerability has been identified in the ltsudo command of Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD products, all through version 8.4.16 on LINX-A64. The vulnerability arises because the 'cmd_ipaddr_conflict' subcommand improperly handles interface-name arguments, copying them into a fixed 20-byte stack buffer using 'strcpy' without any length validation. This flaw allows an attacker in the superadmin group to cause a SUID-root process to abort or potentially elevate privileges by supplying an excessively long interface name.
Users are advised to upgrade to firmware version 8.4.18.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.loytec.com/support/product-security/advisories/8523-dibt-cve-20260526-0005-stack-buffer-overflow-in-cmd_ipaddr_conflict-low | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Loytec LIP-ME201C | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-INX | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-GATE | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-ROC | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-IOB | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-DALI | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-VIS | <= 8.4.16 (semver) |
CPE
Remediation
| |
| Loytec L-PAD | <= 8.4.16 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | New CVE Received | [email protected] |
| Jul 24, 2026 | CVE Modified | CISA-ADP |
Volerion