CVE 8.6 HIGH

Lantronix Provisioning Manager Improper Restriction of XML External Entity Reference_CVE-2025-7766

8.6 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L

Description

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.

Basic Information

ID CVE-2025-7766
Source icscert
Published Jul 22, 2025 at 21:44
Modified Jul 23, 2025 at 19:57

Affected Product

Vendor Lantronix
Product Provisioning Manager
Affected Versions Lantronix Provisioning Manager 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.