An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
References
| Link | Resource |
|---|---|
| http://eds3000ps.com | Not Applicable |
| http://lantronix.com | Product |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 | Third Party Advisory US Government Resource |
Configurations
History
19 Mar 2026, 20:11
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:* cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:* cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:* cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:* |
|
| First Time |
Lantronix eds3008ps1ns
Lantronix eds3008ps1ns Firmware Lantronix eds3016ps1ns Lantronix eds3016ps1ns Firmware Lantronix |
|
| References | () http://eds3000ps.com - Not Applicable | |
| References | () http://lantronix.com - Product | |
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 - Third Party Advisory, US Government Resource |
12 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CWE | CWE-288 |
11 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-11 17:16
Updated : 2026-03-19 20:11
NVD link : CVE-2025-67039
Mitre link : CVE-2025-67039
CVE.ORG link : CVE-2025-67039
JSON object : View
Products Affected
lantronix
- eds3008ps1ns_firmware
- eds3008ps1ns
- eds3016ps1ns_firmware
- eds3016ps1ns
CWE
CWE-288
Authentication Bypass Using an Alternate Path or Channel
