CVE-2025-7766

8.0

Lantronix · Provisioning Manager

Lantronix Provisioning Manager is vulnerable to XML external entity (XXE) attacks in network-supplied configuration files, which allows for unauthenticated remote code execution.

Executive summary

Lantronix Provisioning Manager is affected by a critical XML external entity vulnerability that enables unauthenticated remote code execution on vulnerable host systems.

Vulnerability

The application improperly restricts XML external entity references within configuration files provided by network devices. This flaw allows an unauthenticated attacker to inject malicious XML, resulting in remote code execution on the host system.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational infrastructure, as it grants an attacker the ability to execute arbitrary code with the privileges of the Provisioning Manager service. Given the CVSS score of 8.0, this represents a high-severity threat that could lead to full system compromise, lateral movement across the network, and the exfiltration of sensitive configuration data.

Remediation

Immediate Action: Update Lantronix Provisioning Manager to version 7.10.4 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor network traffic for unusual XML-formatted configuration uploads or unexpected inbound connections originating from network devices to the Provisioning Manager host.

Compensating Controls: Implement strict network segmentation to limit the devices capable of communicating with the Provisioning Manager interface and utilize a Web Application Firewall to inspect and filter malicious XML payloads.

Exploitation status

Public Exploit Available: Yes, a public exploit exists via ExploitDB and a proof-of-concept repository on GitHub.

Analyst recommendation

The risk associated with CVE-2025-7766 is significant due to the potential for unauthenticated remote code execution. Security teams must prioritize the deployment of version 7.10.4 across all affected Lantronix Provisioning Manager instances. Failure to apply this update leaves the environment susceptible to exploitation via readily available attack code.

More Lantronix CVEs

Sources

Originally found and disclosed by Robert McLellan reported this vulnerability to CISA., per the CVE Program record.