Vulnerabilidades en LANTRONIX
25 resultadosAnálisis Vexday
Lantronix apresenta 13 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, com 9 classificadas como críticas (CVSS alto). A fraqueza dominante é injeção de comando (CWE-78), indicando risco significativo de execução remota de código. Não há registros de exploração ativa em wildcard, mas o recente volume de críticas e a natureza severa das falhas exigem priorização imediata de patches.
CVE-2025-67038CRITICALLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 19.3%KEVCVE-2025-7766HIGHLantronix Provisioning Manager Improper Restriction of XML External Entity ReferenceEPSS 1.7%CVE-2025-2567CRITICALLantronix Xport Missing Authentication for Critical FunctionEPSS 0.5%CVE-2025-67034HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.5%CVE-2025-70082MEDIUMLantronix EDS3000PS Unverified Password ChangeEPSS 0.5%CVE-2025-67039CRITICALLantronix EDS3000PS Authentication Bypass Using an Alternate Path or ChannelEPSS 0.4%CVE-2025-67041HIGHLantronix EDS3000PS OS Command InjectionEPSS 0.4%CVE-2025-67035HIGHLantronix EDS5000 OS Command InjectionEPSS 0.4%CVE-2025-67036HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2025-67037HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2023-7237MEDIUMLantronix XPort Weak Encoding for PasswordEPSS 0.3%CVE-2025-4338MEDIUMLantronix Device Installer Improper Restriction of XML External Entity ReferenceEPSS 0.2%CVE-2026-80143CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom readEPSS —CVE-2026-80152CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set script scheduleEPSS —CVE-2026-80151CRITICALLantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs downloadEPSS —CVE-2026-80149HIGHLantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl ParameterEPSS —CVE-2026-80144CRITICALLantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom writeEPSS —CVE-2026-80150HIGHLantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl ParameterEPSS —CVE-2026-80154HIGHLantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation BypassEPSS —CVE-2026-80146CRITICALLantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom readEPSS —