Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.
History

Wed, 23 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Jul 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix
Lantronix provisioning Manager
Vendors & Products Lantronix
Lantronix provisioning Manager

Tue, 22 Jul 2025 22:00:00 +0000

Type Values Removed Values Added
Description Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.
Title Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-07-22T21:44:10.227Z

Updated: 2025-07-23T19:57:57.931Z

Reserved: 2025-07-17T14:41:27.079Z

Link: CVE-2025-7766

cve-icon Vulnrichment

Updated: 2025-07-23T19:57:48.439Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-22T22:15:38.683

Modified: 2025-07-25T15:29:44.523

Link: CVE-2025-7766

cve-icon Redhat

No data.