ZeroHour

CVE-2025-70082

CVSS 4.0
5.1 medium
EPSS
<1%p38
Published
()
Modified
Description

The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.

Vendors
lantronix
Products
eds3016ps1ns firmware, eds3008ps1ns firmware
Weakness
CWE-620, CWE-78, CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news