Junglewise Threat Intelligence

CVE-2025-70082: Lantronix EDS3000PS unverified password change in ltrx_evo

CVE-2025-70082 · Severity: critical · CVSS 9.8 · Published 2026-03-11

Technologies: Lantronix EDS3000PS firmware, Lantronix Eds3016ps1ns Firmware, Lantronix Eds3016ps1ns, Lantronix Eds3008ps1ns, Lantronix Eds3008ps1ns Firmware. Vendors: Lantronix.

Executive brief

Lantronix EDS3000PS is a device server used to connect serial equipment to networks in industrial and enterprise environments. A critical security flaw allows unauthorized individuals to change the administrator password without knowing the current one. If exploited, an attacker could take full control of the device, access sensitive data, or disrupt operations across critical infrastructure sectors.

Technical details

A vulnerability exists in the ltrx_evo component of Lantronix EDS3000PS firmware version 3.1.0.0R2. The flaw (CWE-620) allows the administrator password to be changed without knowledge of the current password. When chained with other vulnerabilities like authentication bypass (CWE-288) or OS command injection (CWE-78), a remote, unauthenticated attacker can achieve full root-level code execution and sensitive information disclosure. The attack is network-reachable and requires no user interaction. Lantronix has released firmware version 3.2.0.0R2 to address this issue.

Affected products

  • Lantronix EDS3000PS firmware 3.1.0.0R2
  • Lantronix EDS3008PS1NS 3.1.0.0R2
  • Lantronix EDS3016PS1NS 3.1.0.0R2

Timeline

  • 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
  • 2026-03-11: disclosed: CVE published in NVD
  • 2026-03-11: patched: Lantronix released firmware 3.2.0.0R2 to address the issue

References

Related threats