Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown

CVE-2021-21876

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21875

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21874

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21873

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21872

Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-13527

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-13528

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-10383

Disclosure Date: May 02, 2019 (last updated November 27, 2024)
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
0
Attacker Value
Unknown

CVE-2018-12925

Disclosure Date: June 28, 2018 (last updated November 26, 2024)
Baseon Lantronix MSS devices do not require a password for TELNET access.
0
Attacker Value
Unknown

CVE-2016-4325

Disclosure Date: May 14, 2016 (last updated November 25, 2024)
Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.
0