CVE Details
Basic Information
| Title |
CVE-2025-4338 |
| Type |
cve |
| Published |
2025-05-22T23:15:19 |
| Last Seen |
2025-05-22T23:23:18 |
CVSS Information
| Base Score |
6.8 (MEDIUM) |
| Attack Vector |
ADJACENT |
| Attack Complexity |
LOW |
| Privileges Required |
NONE |
| User Interaction |
REQUIRED |
| Scope |
UNCHANGED |
| Confidentiality Impact |
HIGH |
| Integrity Impact |
LOW |
| Availability Impact |
LOW |
AI Analysis
| AI Description |
The Lantronix Device installer is vulnerable to XML external entity (XXE) attacks, allowing attackers to access network devices, steal credentials, and potentially modify configurations. |
| AI Severity |
Medium |
| Vendor |
Lantronix |
| Product |
Lantronix Device Installer |
| Affected Version |
|
Additional Information
| CVE List |
CVE-2025-4338 |
| CWE List |
CWE-611 |
| Bulletin Family |
cve |
Description
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify…
CVSS Score Summary
Base Score: %!f(string=#) (MEDIUM)
View Full CVE Details