LOYTEC L-IP BACnet/IP Routers Improper Privilege Management (CVE-2026-12502)

info Tenable OT Security Plugin ID 505946

Description

A local attacker who is a member of the 'superadmin' group can reset the password of any LARM user on a LOYTEC L-IP BACnet/IP router, including the 'larmapp' service account, via the 'set-passwd' subcommand of the '/usr/bin/ltsudo' utility. This bypasses the authorization checks that should limit password resets to the account's own owner.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Plugin Details

Severity: Info

ID: 505946

Published: 9/7/2026

Updated: 9/7/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.15

Reference Information

CVE: CVE-2026-12502