CVE-2016-4325: Critical severity lantronix xprintserver firmware vulnerability
Published May 14, 2016
·Updated
Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.
Affected Software
1 affected component
Lantronix Xprintserver Firmware<=3.3.0
Event History
May 14, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4325?
CVE-2016-4325 has a significant severity rating due to the presence of hardcoded credentials allowing remote root access.
2
How do I fix CVE-2016-4325?
To fix CVE-2016-4325, upgrade your Lantronix xPrintServer devices to firmware version 5.0.1-65 or later.
3
Which devices are affected by CVE-2016-4325?
CVE-2016-4325 affects Lantronix xPrintServer devices running firmware versions before 5.0.1-65.
4
What kind of attack is possible with CVE-2016-4325?
Attackers can exploit CVE-2016-4325 to gain unauthorized remote root access to affected devices due to hardcoded credentials.
5
Are there any mitigations available for CVE-2016-4325?
The primary mitigation for CVE-2016-4325 is to apply the firmware update to eliminate the hardcoded credentials.