CVE-2025-7766: Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix Provisioning Managerto a version that resolves this vulnerability.Fixed in 7.10.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7766?
CVE-2025-7766 has been classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2025-7766?
To fix CVE-2025-7766, apply the latest security patch provided by Lantronix for the Provisioning Manager.
What type of attack is associated with CVE-2025-7766?
CVE-2025-7766 is associated with XML external entity (XXE) attacks.
Who is affected by CVE-2025-7766?
Any system running Lantronix Provisioning Manager that accepts configuration files from network devices is potentially affected by CVE-2025-7766.
What are the potential impacts of CVE-2025-7766?
The potential impacts of CVE-2025-7766 include unauthorized access and execution of malicious code on affected systems.