60
CVE-2025-70082
—CVSS 4.0
5.1 medium
EPSS
<1%p38
Published
()
Modified
Description
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
- Vendors
- lantronix
- Products
- eds3016ps1ns firmware, eds3008ps1ns firmware
- Weakness
- CWE-620, CWE-78, CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X