Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22376 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. |
Solution
Lantronix has provided a fix and recommends users update to v7.10.4 https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/105906637/Latest+Version+of+Lantronix+Provisioning+Manager+LPM or later.
Workaround
No workaround given by the vendor.
Wed, 23 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lantronix
Lantronix provisioning Manager |
|
| Vendors & Products |
Lantronix
Lantronix provisioning Manager |
Tue, 22 Jul 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed. | |
| Title | Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-07-23T19:57:57.931Z
Reserved: 2025-07-17T14:41:27.079Z
Link: CVE-2025-7766
Updated: 2025-07-23T19:57:48.439Z
Status : Awaiting Analysis
Published: 2025-07-22T22:15:38.683
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-7766
No data.
OpenCVE Enrichment
Updated: 2025-07-23T17:35:58Z
EUVD