CVE-2018-12925: Critical severity lantronix mss firmware vulnerability
Published Jun 28, 2018
·Updated
Baseon Lantronix MSS devices do not require a password for TELNET access.
Affected Software
2 affected components
Lantronix Mss Firmware
Lantronix MSS
Event History
Jun 28, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-12925?
CVE-2018-12925 is considered a high severity vulnerability due to the lack of authentication for TELNET access.
2
How do I fix CVE-2018-12925?
To fix CVE-2018-12925, disable TELNET access and use SSH instead for secure remote management.
3
What devices are affected by CVE-2018-12925?
CVE-2018-12925 affects Baseon Lantronix MSS devices running specific firmware versions.
4
What are the risks associated with CVE-2018-12925?
The risks of CVE-2018-12925 include unauthorized access to device settings and potential exploitation by attackers.
5
Is there a workaround for CVE-2018-12925?
A potential workaround for CVE-2018-12925 is to restrict access to the TELNET service through network firewalls.