CVE-2025-67039

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:*

History

05 Jul 2026, 17:17

Type Values Removed Values Added
References
  • {'url': 'http://eds3000ps.com', 'tags': ['Not Applicable'], 'source': 'cve@mitre.org'}

05 Jul 2026, 02:17

Type Values Removed Values Added
References
  • {'url': 'http://lantronix.com', 'tags': ['Product'], 'source': 'cve@mitre.org'}

23 Jun 2026, 19:09

Type Values Removed Values Added
CPE cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:*

19 Mar 2026, 20:11

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Lantronix EDS3000PS 3.1.0.0R2. La autenticación en las páginas de administración puede ser eludida al añadir un sufijo específico a la URL y al enviar una cabecera de autorización que utiliza 'admin' como nombre de usuario.
CPE cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
First Time Lantronix eds3008ps1ns
Lantronix eds3008ps1ns Firmware
Lantronix eds3016ps1ns
Lantronix eds3016ps1ns Firmware
Lantronix
References () http://eds3000ps.com - () http://eds3000ps.com - Not Applicable
References () http://lantronix.com - () http://lantronix.com - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 - Third Party Advisory, US Government Resource

12 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-288

11 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 17:16

Updated : 2026-07-05 17:17


NVD link : CVE-2025-67039

Mitre link : CVE-2025-67039

CVE.ORG link : CVE-2025-67039


JSON object : View

Products Affected

lantronix

  • eds3008ps1ns
  • eds3016ps1ns
  • eds3008ps1ns_firmware
  • eds3016ps1ns_firmware
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel