CVE-2025-70082

9.8

Lantronix · EDS3000PS

A vulnerability in the Lantronix EDS3000PS ltrx_evo component allows unauthenticated attackers to execute arbitrary code and retrieve sensitive information.

Executive summary

A critical remote code execution vulnerability in the Lantronix EDS3000PS allows unauthenticated attackers to execute arbitrary commands and exfiltrate sensitive data.

Vulnerability

The flaw exists within the ltrx_evo component and permits unauthenticated remote attackers to execute arbitrary system code. This vulnerability allows for a complete compromise of the device's security posture.

Business impact

The ability for an unauthenticated attacker to execute arbitrary code presents a catastrophic risk, including the potential for full system takeover, lateral movement within the network, and the theft of sensitive operational data. The 9.8 CVSS score reflects the high severity of a remote, unauthenticated RCE condition.

Remediation

Immediate Action: Users should consult the vendor's security advisory (ICSA-26-069-02) to verify the availability of a firmware update and apply it immediately.

Proactive Monitoring: Continuously monitor device performance and system logs for unexpected processes or unauthorized connections originating from the device.

Compensating Controls: If a patch is not yet available, isolate the device from external networks using a segmented VLAN and ensure it is not accessible via the public internet.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical severity and the potential for remote code execution, this device must be treated as a high-risk asset. Administrators must prioritize applying vendor-issued patches as soon as they are made available to prevent exploitation of this RCE vulnerability.

More Lantronix CVEs