CVE-2025-67039
Received
Received - Intake
Authentication Bypass in Lantronix EDS3000PS Management Interface
Publication date: 2026-03-11
Last updated on: 2026-03-19
Assigner: MITRE
Description
Description
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lantronix | eds3016ps1ns_firmware | 3.1.0.0 |
| lantronix | eds3008ps1ns_firmware | 3.1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |