CVE-2025-4338 describes an XML External Entity (XXE) vulnerability in Lantronix Device Installer, affecting its handling of configuration files from network devices. This medium-severity vulnerability (CVSS 6.8) allows an attacker to gain credentials, modify device configurations, or potentially access the host running the software or user password hashes. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and there's no active exploitation or significant community discussion, the potential impact warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Lantronix | Device Installer | >= 0, <= 4.4.0.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.