Show filters
35 Total Results
Displaying 21-30 of 35
Sort by:
Attacker Value
Unknown
CVE-2021-21876
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authenticated HTTP requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21875
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21874
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21873
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21872
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-13527
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An authentication bypass vulnerability exists in the Web Manager functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause increased privileges. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-13528
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
An information disclosure vulnerability exists in the Web Manager and telnet CLI functionality of Lantronix XPort EDGE 3.0.0.0R11, 3.1.0.0R9, 3.4.0.0R12 and 4.2.0.0R7. A specially crafted HTTP request can cause information disclosure. An attacker can sniff the network to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-10383
Disclosure Date: May 02, 2019 (last updated November 27, 2024)
Lantronix SecureLinx Spider (SLS) 2.2+ devices have XSS in the auth.asp login page.
0
Attacker Value
Unknown
CVE-2018-12925
Disclosure Date: June 28, 2018 (last updated November 26, 2024)
Baseon Lantronix MSS devices do not require a password for TELNET access.
0
Attacker Value
Unknown
CVE-2016-4325
Disclosure Date: May 14, 2016 (last updated November 25, 2024)
Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.
0