TLS Certificate Generation Function Improper Input Validation
Description
An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Denial-of-Service (DoS) condition which can only be reverted via a factory reset. This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper input validation in TLS certificate generation in Lanner IAC-AST2500A BMC firmware allows authenticated remote attackers to cause a permanent DoS requiring factory reset.
Vulnerability
An improper input validation vulnerability exists in the TLS certificate generation function of Lanner IAC-AST2500A BMC firmware version 1.10.0. This issue allows an authenticated remote attacker to trigger a Denial-of-Service (DoS) condition that can only be reverted via a factory reset [1][2].
Exploitation
An attacker with network access and valid authentication credentials can exploit this vulnerability by sending a crafted request to the TLS certificate generation function. The improper input validation causes the BMC to enter an unrecoverable state, requiring physical access to perform a factory reset [2].
Impact
Successful exploitation results in a complete denial of service of the BMC, making it inaccessible to users. The device cannot be recovered without a factory reset, which erases all configuration and data. The CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) [2].
Mitigation
Lanner has released updated firmware versions that fix the issue, available from Lanner technical support. Asset owners should apply the update as soon as possible. No workarounds are documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2= 1.10.0+ 1 more
- (no CPE)range: = 1.10.0
- (no CPE)range: 1.10.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.