Ltsecurity · Ltk3500Sf · CVE-2026-47116
**Name of the Vulnerable Software and Affected Versions**
LTSecurity LTK3500SF (affected versions not specified)
**Description**
The device contains hard-coded credentials where the root and guest account passwords are stored in the `/etc/shadow` file as weak hashes. These hashes can be recovered using dictionary-based cracking tools. Once recovered, the credentials allow authentication via Telnet and SSH services, granting root-level access to the operating system. Exploitation depends on whether the Telnet or SSH services are active, as they may not start automatically at boot.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.