Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-70082

An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component

Mitigation only
Fix from $2,300 2026-03-11
Eds5032 Firmware CRITICAL 9.8
CVE-2025-67038 KEVEPSS 14%

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. …

Mitigation only
Fix from $2,300 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.8
CVE-2025-67041

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly saniti…

Mitigation only
Fix from $2,300 2026-03-11
Eds3016ps1ns Firmware CRITICAL 9.1
CVE-2025-67039

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to th…

Mitigation only
Fix from $2,300 2026-03-11
Eds5032 Firmware CRITICAL 9.8
CVE-2025-67035

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due…

Mitigation only
Fix from $2,300 2026-03-11
Eds5032 Firmware HIGH 8.8
CVE-2025-67036

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing s…

Mitigation only
Fix from $1,950 2026-03-11
Eds5032 Firmware HIGH 8.8
CVE-2025-67037

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a t…

Mitigation only
Fix from $1,950 2026-03-11
Eds5032 Firmware HIGH 8.8
CVE-2025-67034

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL …

Mitigation only
Fix from $1,950 2026-03-11
Xport Edge Firmware HIGH 7.5
CVE-2023-7237

Lantronix XPort sends weakly encoded credentials within web request headers.

Mitigation only
Fix from $1,950 2024-01-23
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21881EPSS 36%

An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A spe…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21883EPSS 6%

An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21889

A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A special…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21892EPSS 30%

A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A sp…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21884EPSS 5%

An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-cra…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21887

A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU).…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21888

An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21890

A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). …

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21891

A stack-based buffer overflow vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). …

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21894

A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially cra…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware HIGH 8.8
CVE-2021-21882EPSS 6%

An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted …

No fix yet
Fix from $1,950 2021-12-22
Premierwave 2050 Firmware HIGH 7.2
CVE-2021-21880

A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted H…

No fix yet
Fix from $1,950 2021-12-22
Premierwave 2050 Firmware HIGH 7.2
CVE-2021-21885

A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP …

No fix yet
Fix from $1,950 2021-12-22
Premierwave 2050 Firmware HIGH 7.2
CVE-2021-21895

A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially cra…

No fix yet
Fix from $1,950 2021-12-22
Premierwave 2050 Firmware MEDIUM 6.5
CVE-2021-21896

A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specia…

No fix yet
Fix from $1,600 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.9
CVE-2021-21872EPSS 6%

An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A spec…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21873

A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP reque…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21874

A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP reque…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21875

A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP reques…

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21876

Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger …

No fix yet
Fix from $2,300 2021-12-22
Premierwave 2050 Firmware CRITICAL 9.1
CVE-2021-21877

Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigge…

No fix yet
Fix from $2,300 2021-12-22