CVE-2025-70082

Summary

The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.

Affected Software

VendorProductVersion RangeStatus
LantronixEDS3000PS series0 <= 3.1.0.0R2affected
LantronixEDS3000PS series3.2.0.0R2unaffected

Weaknesses

  • CWE-620: CWE-620

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References