CVE-2025-70082

The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-11 17:16

Updated : 2026-09-04 21:17


NVD link : CVE-2025-70082

Mitre link : CVE-2025-70082

CVE.ORG link : CVE-2025-70082


JSON object : View

Products Affected

lantronix

  • eds3008ps1ns_firmware
  • eds3016ps1ns_firmware
  • eds3016ps1ns
  • eds3008ps1ns
CWE
CWE-620

Unverified Password Change

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-288

Authentication Bypass Using an Alternate Path or Channel