CVE-2025-67039: Critical severity Lantronix EDS3000PS vulnerability
Published Mar 11, 2026
·Updated
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
Affected Software
5 affected components
Lantronix EDS3000PS
All of the following
Lantronix Eds3016ps1ns Firmware=3.1.0.0r2
Lantronix Eds3016ps1ns
All of the following
Lantronix Eds3008ps1ns Firmware=3.1.0.0r2
Lantronix Eds3008ps1ns
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software