Lantronix
lantronix
43 CVEs • 25 products
Products (25)
Click to collapseToggle
Products (25)
Click to collapse
CVEs (43)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attack...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can m...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an a...Show more |
A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 A local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted series of HTTP requests can lead to local file inclusion...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability. |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An...Show more |
1Lantronix 1Xport Edge Firmware Jun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause informati...Show more |
1Lantronix 2Sgx Firmware Xport Edge FirmwareJun 17, 2026 Dec 18, 2020 N/A· v4 4.5 MEDIUM· v3 3.5 LOW· v2 An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An...Show more |
1Lantronix 1Securelinx Spider Firmware Nov 21, 2024 May 2, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page. |
Baseon Lantronix MSS devices do not require a password for TELNET access. |
1Lantronix 1Xprintserver Firmware May 6, 2026 May 14, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors. |
Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for requests that modify configuration, as demonstrated by executing arbitr...Show more |
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action. |