Executive brief
Lantronix EDS3000PS is a device server used to connect serial equipment to Ethernet networks for remote management. A security flaw allows unauthorized individuals to bypass the login screen and access the device's management interface. This could allow an attacker to change system settings, intercept data, or gain full control over the connected infrastructure.
Technical details
An authentication bypass vulnerability (CWE-288) exists in the management pages of Lantronix EDS3000PS version 3.1.0.0R2. The flaw is triggered by appending a specific suffix to the URL and providing an Authorization header with the username 'admin'. This allows a remote, unauthenticated attacker to bypass security controls and access administrative functions. When chained with other vulnerabilities like CVE-2025-70082, an attacker can change the administrator password without knowing the current one. Lantronix recommends upgrading to EDS3000PS version 3.2.0.0R2 to resolve this issue.
Affected products
- Lantronix EDS3000PS firmware 3.1.0.0R2
- Lantronix EDS3008PS1NS firmware 3.1.0.0R2
- Lantronix EDS3016PS1NS firmware 3.1.0.0R2
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE published to NVD