Description
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Published: 2026-03-11
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Administrator Password Reset
Action: Apply Patch
AI Analysis

Impact

Lantronix firmware for the EDS3000PS series allows an attacker to change the administrator password without providing the current password, effectively bypassing normal authentication checks. This flaw can be chained with an authentication‑bypass vulnerability to grant unauthenticated users the ability to modify the admin credentials, thereby gaining full administrative control over the device. The weakness corresponds to insufficient authentication enforcement, as identified by CWE‑288 and related input validation problems.

Affected Systems

Hardware products affected are the Lantronix EDS3008PS1NS and EDS3016PS1NS models running firmware version 3.1.0.0R2. The vendor recommends upgrading to firmware 3.2.0.0R2 or later. Although the CVE title references the broader EDS3000PS series, the CPE strings specifically point to these two hardware variants, indicating that the vulnerability applies to them at the cited firmware revision.

Risk and Exploitability

The CVSS base score of 5.1 classifies this flaw as moderate, while an EPSS estimate of less than 1 % suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. If an attacker can reach the device’s password change endpoint—potentially without verifying the current password or through an authentication bypass—they could change the administrator credentials and take full control. The attack vector is likely over the network, requiring the device to be reachable from the attacker’s environment.

Generated by OpenCVE AI on September 4, 2026 at 23:51 UTC.

Remediation

Vendor Solution

Latronix has released the following updates addressing this vulnerability. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).


OpenCVE Recommended Actions

  • Upgrade the device firmware to version 3.2.0.0R2 or later to eliminate the flaw.
  • If an immediate firmware upgrade is not possible, isolate affected devices by restricting network access, placing them behind a firewall or VLAN, and limiting management access to trusted hosts.
  • Enable detailed device logging and monitor for unexpected administrator password change requests; consider disabling or restricting the ltrx_evo service if it is not required.

Generated by OpenCVE AI on September 4, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Title Arbitrary Code Execution via ltrx_evo Component in Lantronix EDS3000PS Firmware 3.1.0.0R2 Lantronix EDS3000PS Unverified Password Change
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Fri, 20 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via ltrx_evo Component in Lantronix EDS3000PS Firmware 3.1.0.0R2

Thu, 19 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix eds3008ps1ns
Lantronix eds3008ps1ns Firmware
Lantronix eds3016ps1ns
Lantronix eds3016ps1ns Firmware
CPEs cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
Vendors & Products Lantronix eds3008ps1ns
Lantronix eds3008ps1ns Firmware
Lantronix eds3016ps1ns
Lantronix eds3016ps1ns Firmware

Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix
Lantronix eds3000ps
Vendors & Products Lantronix
Lantronix eds3000ps

Wed, 11 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-288
CWE-620
CWE-78
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component
References

Subscriptions

Lantronix Eds3000ps Eds3008ps1ns Eds3008ps1ns Firmware Eds3016ps1ns Eds3016ps1ns Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T20:39:12.079Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70082

cve-icon Vulnrichment

Updated: 2026-03-11T18:11:51.682Z

cve-icon NVD

Status : Modified

Published: 2026-03-11T17:16:53.197

Modified: 2026-09-04T21:17:24.267

Link: CVE-2025-70082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:07Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel

  • CWE-620

    Unverified Password Change

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')