CRITICAL🇵🇱 Wersja polska

CVE-2025-67039

CVSS 9.1v3.1pub. 2026-03-11upd. 2026-07-05

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.

🤖 AI Analysis
How it works

The vulnerability (CWE-288 — Authentication Bypass Using an Alternate Path or Channel) involves adding a specific suffix to the management page URL and sending an Authorization header with the username 'admin', which completely bypasses the identity verification mechanism. The server incorrectly treats such a request as authorized without verifying actual credentials. The attack does not require knowledge of the password or any prior session.

Impact

An attacker gains unauthorized access to the device's administrative panel, enabling them to modify configuration, take control of the device, and potentially compromise the confidentiality and integrity of data transmitted over the network.

Mitigation & patch

Apply patches available from the manufacturer according to references (ICS-CERT security advisory: ICSA-26-069-02). Until the update is applied, it is recommended to restrict network access to the device management interface only to trusted hosts and isolate devices in the OT/ICS network behind a firewall.

Who is affected

Lantronix EDS3016PS1NS and EDS3008PS1NS with software version 3.1.0.0R2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Lantronix Eds3008ps1ns

    HW
    Lantronix
    all versions
  • Lantronix Eds3008ps1ns Firmware

    OS
    Lantronix
    3.1.0.0r2
  • Lantronix Eds3016ps1ns

    HW
    Lantronix
    all versions
  • Lantronix Eds3016ps1ns Firmware

    OS
    Lantronix
    3.1.0.0r2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-67041CRITICAL9.8PL ✓same product

Command injection w parametrze host klienta TFTP urządzeń Lantronix EDS3000PS

CVE-2025-70082CRITICAL9.8PL ✓same product

RCE i ujawnienie danych w Lantronix EDS3000PS via ltrx_evo

CVE-2025-67038CRITICAL9.8⚠ KEVPL ✓same vendor

Command injection w Lantronix EDS5000 – wykonanie poleceń jako root

CVE-2025-67035CRITICAL9.8PL ✓same vendor

OS command injection w Lantronix EDS5000 — wykonanie kodu jako root

CVE-2021-21872CRITICAL9.9PL ✓same vendor

Command Injection w Web Manager Diagnostics Lantronix PremierWave 2050