An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
References
Configurations
History
No history.
Information
Published : 2026-03-11 17:16
Updated : 2026-09-04 21:17
NVD link : CVE-2025-67039
Mitre link : CVE-2025-67039
CVE.ORG link : CVE-2025-67039
JSON object : View
Products Affected
lantronix
- eds3008ps1ns_firmware
- eds3016ps1ns_firmware
- eds3016ps1ns
- eds3008ps1ns
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
