VYPR

Vendor CVEs

Lantronix

All CVEs

60 total · sorted by risk
  • CVE-2020-13528MedDec 18, 2020
    risk 0.35cvss 5.3epss 0.03

    An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger…

  • CVE-2021-21878MedDec 22, 2021
    risk 0.32cvss 4.9epss 0.01

    A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion. An attacker can make a series of authenticated HTTP…

  • CVE-2020-13527MedDec 18, 2020
    risk 0.29cvss 4.5epss 0.01

    An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this…

  • CVE-2021-21886MedDec 22, 2021
    risk 0.28cvss 4.3epss 0.02

    A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make an authenticated HTTP request to trigger this vulnerability.

  • CVE-2025-70082LowMar 11, 2026
    risk 0.18cvss 2.7epss 0.00

    The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.

  • CVE-2014-9003Nov 20, 2014
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for requests that modify configuration, as demonstrated by executing arbitrary commands using the c parameter in the rpc action.

  • CVE-2014-9002Nov 20, 2014
    risk 0.00cvss —epss 0.05

    Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.

  • CVE-2008-7201Sep 10, 2009
    risk 0.00cvss —epss 0.01

    Lantronix MSS485-T allows remote attackers to cause a denial of service (unstable performance and service loss) via certain vulnerability scans, as demonstrated using (1) Nessus and (2) nmap.

  • CVE-2007-5981Nov 15, 2007
    risk 0.00cvss —epss 0.01

    Lantronix SCS3200 does not properly handle public-key requests, which allows remote attackers to cause a denial of service (unresponsive device) via unspecified keyscan requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third…

  • CVE-2005-2189Jul 11, 2005
    risk 0.00cvss —epss 0.01

    Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.

Page 2 of 2