Input validation error in LANTIME Operating System Firmware (LTOS) - #VU109399

 

Input validation error in LANTIME Operating System Firmware (LTOS) - #VU109399

Published: May 18, 2025


Vulnerability identifier: #VU109399
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform spoofing attack.

The vulnerability exists due to an error when displaying users. User account with a name that consists of parts of a system username is not displayed in the web interface, which can allow creation of persisted hidden user accounts.


Affected software

LANTIME Operating System Firmware (LTOS)

Remediation

Install updates from vendor's website.

LANTIME Operating System Firmware (LTOS) - update to 7.08.002

External References

Related Security Bulletins