---
id: CVE-2026-47116
title: >-
  LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the
  root and guest account passwords are stored in /etc/shadow as weak hashes
  recoverable with dictionary-based cracking tools
summary: >-
  LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the
  root and guest account passwords are stored in /etc/shadow as weak hashes
  recoverable with dictionary-based cracking tools. The recovered credentials
  authenti…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-798
vendor: LTSecurity
product: LTK3500SF
affected:
  - LTK3500SF AC3F_V1.1.0_build191121
published: '2026-09-22'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47116'
references:
  - url: >-
      https://github.com/AndreaLandriscina/Hardcoded-Credentials-in-LTSecurity-LTK3500SF
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ltsecurity-ltk3500sf-hard-coded-credentials-via-telnet-ssh
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00512
epssPercentile: 0.41064
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-23T14:31:15.173205Z'
ingestedAt: '2026-09-22T20:10:15.102Z'
---

## Overview

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to the operating system. These services are not confirmed to start automatically at boot, so exploitation requires Telnet or SSH to be running, whether enabled by the device configuration or started manually.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
