CVE-2025-29570

An issue in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 allows a local attacker to escalate privileges via the function tftp_image_check of a binary named rc.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:szlbt:lbt-t300-t400_firmware:3.2:*:*:*:*:*:*:*
cpe:2.3:h:szlbt:lbt-t300-t400:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-04-03 20:15

Updated : 2025-08-20 02:50


NVD link : CVE-2025-29570

Mitre link : CVE-2025-29570

CVE.ORG link : CVE-2025-29570


JSON object : View

Products Affected

szlbt

  • lbt-t300-t400
  • lbt-t300-t400_firmware
CWE
CWE-276

Incorrect Default Permissions