Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.
Metrics
Affected Vendors & Products
References
History
Fri, 23 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application. | |
Title | Lantronix Device Installer Improper Restriction of XML External Entity Reference | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-05-22T23:00:02.999Z
Updated: 2025-05-23T13:34:42.688Z
Reserved: 2025-05-05T16:00:14.779Z
Link: CVE-2025-4338

Updated: 2025-05-23T13:34:36.732Z

Status : Awaiting Analysis
Published: 2025-05-22T23:15:19.400
Modified: 2025-05-23T15:54:42.643
Link: CVE-2025-4338

No data.