Input validation error in LANTIME Operating System Firmware (LTOS) - #VU109399
Published: May 18, 2025
Vulnerability identifier: #VU109399
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform spoofing attack.
The vulnerability exists due to an error when displaying users. User account with a name that consists of parts of a system username is not displayed in the web interface, which can allow creation of persisted hidden user accounts.
Affected software
LANTIME Operating System Firmware (LTOS)
Remediation
Install updates from vendor's website.
LANTIME Operating System Firmware (LTOS) - update to 7.08.002