CVE-2025-67039

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.

Credits

Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS3000PS series to CISA.

References