CVE-2026-47116

Summary

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can use the recovered credentials to authenticate via Telnet or SSH and obtain full root-level access to the operating system.

Affected Software

VendorProductVersion RangeStatus
LTSecurityLTK3500SFAC3F_V1.1.0_build191121affected

Weaknesses

  • CWE-798: Use of Hard-coded Credentials

References