Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-47116
LTSecurity LTK3500SF Hard-coded Credentials via Telnet/SSH
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N N H H H 9.2 .0051 41.5 —
AFFECTED
Product Versions Fixed
LTK3500SF AC3F_V1.1.0_build191121 – —
TIMELINE
May 18 Reserved by VulnCheck
Sep 22 Published (CNA: VulnCheck)
Sep 23 EXPLOIT PUBLISHED — CVE-2026-47116 (LTSecurity LTK3500SF). Public exploit reference added.
Sep 23 RESCORED — CVE-2026-47116 (LTSecurity LTK3500SF). CVSS 9.3 → 9.2 (NVD).
Description
LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenticate against the device's Telnet and SSH services and grant root-level access to the operating system. These services are not confirmed to start automatically at boot, so exploitation requires Telnet or SSH to be running, whether enabled by the device configuration or started manually.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| May 18, 2026 | Reserved | Reserved by VulnCheck |
| September 22, 2026 | Published | Published (CNA: VulnCheck) |
| September 23, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-47116 (LTSecurity LTK3500SF). Public exploit reference added. |
| September 23, 2026 | RESCORED | RESCORED — CVE-2026-47116 (LTSecurity LTK3500SF). CVSS 9.3 → 9.2 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| LTSecurity | LTK3500SF | — | AC3F_V1.1.0_build191121 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-47116 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.