CVE-2025-4338 - CERT CVE
ID CVE-2025-4338
Sažetak Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.
Reference
CVSS
Base: 6.8
Impact: 4.7
Exploitability:2.1
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
HIGH LOW LOW
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Zadnje važnije ažuriranje 23-05-2025 - 15:54
Objavljeno 22-05-2025 - 23:15