Skip to main content
CRITICAL

CVE-2026-47116

CVSS v3

9.8

CRITICAL

EPSS Score

0.5 %

exploit probability, as of 2026-09-29

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to the operating system. These services are not confirmed to start automatically at boot, so exploitation requires Telnet or SSH to be running, whether enabled by the device configurati

Technical details

Published
2026-09-22
Last Modified
2026-09-23

Frequently asked questions

What is CVE-2026-47116?

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to the operating system. These services are not confirmed to start automatically at boot, so exploitation requires Telnet or SSH to be running, whether enabled by the device configurati

Is CVE-2026-47116 actively exploited?

Active exploitation of CVE-2026-47116 has not been confirmed. Its EPSS score was 0.5% on 2026-09-29, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-47116?

CVE-2026-47116 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2026-47116 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key