CVE-2025-70082 is a critical arbitrary code execution and information disclosure vulnerability affecting Lantronix EDS3000PS series devices, specifically firmware version 3.1.0.0R2, including models like EDS3008PS1NS and EDS3016PS1NS. Rated 9.8 CRITICAL, this flaw can be exploited remotely over the network with low complexity and no authentication, allowing an attacker to gain full control and access sensitive data. A successful exploit results in high impact to confidentiality, integrity, and availability. Despite its severity, there is currently no public exploit code available in common repositories like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog. While a CISA alert has been issued, community discussion and media coverage remain limited, and its EPSS score suggests a very low likelihood of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0.0r2CPE matchmatch criteria | cpe:2.3:o:lantronix:eds3016ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:* | ||
3.1.0.0r2CPE matchmatch criteria | cpe:2.3:o:lantronix:eds3008ps1ns_firmware:3.1.0.0r2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.