Home

Description

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.

PUBLISHED Reserved 2025-07-17 | Published 2025-07-22 | Updated 2025-07-23 | Assigner icscert




HIGH: 8.6CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

HIGH: 8.0CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-611 Improper Restriction of XML External Entity Reference

Product status

Default status
unaffected

Any version
affected

Credits

Robert McLellan reported this vulnerability to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-203-02

ltrxdev.atlassian.net/...+Lantronix+Provisioning+Manager+LPM

cve.org (CVE-2025-7766)

nvd.nist.gov (CVE-2025-7766)

Download JSON