CyberRota Analysis
AI-GeneratedThe vulnerability affects Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, and L-PAD devices running versions up to 8.4.16, allowing authenticated `larmapp` users to exploit improper link resolution in `/usr/bin/larm_starter`. This flaw can be leveraged to make `/etc/passwd` writable by the `larmapp` group, potentially leading to root privilege escalation through a symlink attack on the SSL certificate file. Organizations using these devices should prioritize remediation to mitigate the risk of unauthorized access and system compromise.
Original NVD Description
Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an authenticated `larmapp` attacker to make `/etc/passwd` writable by the `larmapp` group (leading to root privilege escalation) via a symlink attack on `/etc/lighttpd/ssl/server.pem`.