Vulnerabilities in Lantronix

25 results
Vexday analysis

Lantronix apresenta um pequeno portfólio de risco com 4 CVEs catalogadas, nenhuma sob ataque ativo no momento. A única vulnerabilidade crítica (CVSS) está associada a injeção XML (CWE-611), classe conhecida por impacto severo em processamento de dados. Sem publicações nos últimos 90 dias, o risco mantém-se estável, embora a tipologia de vulnerabilidade exija atenção em ambientes que processam entrada XML não sanitizada.

CVE-2025-67038CRITICALLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 19.3%KEVCVE-2025-7766HIGHLantronix Provisioning Manager Improper Restriction of XML External Entity ReferenceEPSS 1.7%CVE-2026-80152CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set script scheduleEPSS 1.7%CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS 1.7%CVE-2026-80145CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs passwordEPSS 1.7%CVE-2026-80143CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom readEPSS 1.5%CVE-2026-80144CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom writeEPSS 1.5%CVE-2026-80155CRITICALLantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprintf Path TruncationEPSS 1.0%CVE-2026-80147CRITICALLantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom writeEPSS 0.8%CVE-2026-80146CRITICALLantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom readEPSS 0.8%CVE-2026-80156CRITICALLantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation BypassEPSS 0.7%CVE-2026-80154HIGHLantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation BypassEPSS 0.6%CVE-2026-80150HIGHLantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl ParameterEPSS 0.6%CVE-2026-80149HIGHLantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl ParameterEPSS 0.6%CVE-2026-80148HIGHLantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username TruncationEPSS 0.6%CVE-2025-2567CRITICALLantronix Xport Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-67034HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.5%CVE-2025-70082MEDIUMLantronix EDS3000PS Unverified Password ChangeEPSS 0.5%CVE-2025-67039CRITICALLantronix EDS3000PS Authentication Bypass Using an Alternate Path or ChannelEPSS 0.4%CVE-2025-67041HIGHLantronix EDS3000PS OS Command InjectionEPSS 0.4%