An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
The vulnerability (CWE-288 — Authentication Bypass Using an Alternate Path or Channel) involves adding a specific suffix to the management page URL and sending an Authorization header with the username 'admin', which completely bypasses the identity verification mechanism. The server incorrectly treats such a request as authorized without verifying actual credentials. The attack does not require knowledge of the password or any prior session.
An attacker gains unauthorized access to the device's administrative panel, enabling them to modify configuration, take control of the device, and potentially compromise the confidentiality and integrity of data transmitted over the network.
Apply patches available from the manufacturer according to references (ICS-CERT security advisory: ICSA-26-069-02). Until the update is applied, it is recommended to restrict network access to the device management interface only to trusted hosts and isolate devices in the OT/ICS network behind a firewall.
Lantronix EDS3016PS1NS and EDS3008PS1NS with software version 3.1.0.0R2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NLantronix Eds3008ps1ns
HWLantronixall versionsLantronix Eds3008ps1ns Firmware
OSLantronix3.1.0.0r2Lantronix Eds3016ps1ns
HWLantronixall versionsLantronix Eds3016ps1ns Firmware
OSLantronix3.1.0.0r2
Related vulnerabilities
Command injection w parametrze host klienta TFTP urządzeń Lantronix EDS3000PS
RCE i ujawnienie danych w Lantronix EDS3000PS via ltrx_evo
Command injection w Lantronix EDS5000 – wykonanie poleceń jako root
OS command injection w Lantronix EDS5000 — wykonanie kodu jako root
Command Injection w Web Manager Diagnostics Lantronix PremierWave 2050