CVE-2025-70082: Lantronix EDS3000PS Unverified Password Change
Published Mar 11, 2026
·Updated
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Affected Software
5 affected components
Lantronix EDS3000PS
All of the following
Lantronix Eds3016ps1ns Firmware=3.1.0.0r2
Lantronix Eds3016ps1ns
All of the following
Lantronix Eds3008ps1ns Firmware=3.1.0.0r2
Lantronix Eds3008ps1ns
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix EDS3000PS seriesto a version that resolves this vulnerability.Fixed in 3.2.0.0R2
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software