An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Lantronix Eds3016ps1ns_Firmware
cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
|
— | — |
|
Lantronix Eds3016ps1ns
cpe:2.3:h:lantronix:eds3016ps1ns:-:*:*:*:*:*:*:*
|
— | — |
|
Lantronix Eds3008ps1ns_Firmware
cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0:r2:*:*:*:*:*:*
|
— | — |
|
Lantronix Eds3008ps1ns
cpe:2.3:h:lantronix:eds3008ps1ns:-:*:*:*:*:*:*:*
|
— | — |