Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-4338

Опубликовано: 22 мая 2025
Источник: nvd
CVSS3: 6.8
EPSS Низкий

Описание

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 6.8
github
9 месяцев назад

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or the password hash of the user running the application.

EPSS

Процентиль: 2%
0.00014
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-611