Lantronix manufactures a focused line of remote access and serial communication appliances, notably the PremierWave and EDS product families, that serve industrial and enterprise environments where they often bridge legacy systems to modern networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur persistently across its firmware and device interfaces through command injection, path traversal, code injection, and memory-safety weaknesses that are characteristic of embedded appliances with limited update cadence. These weakness classes reflect the parsing and privilege-boundary challenges inherent to devices that handle untrusted input from multiple network interfaces and must execute administrative functions. Defenders should prioritize inventory and network isolation of affected Lantronix devices, since the vendor's narrow but strategically positioned product line means that patching cycles and firmware updates may lag behind disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lantronix over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67038CRITICAL An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concat | Mar 11, 2026 | 9.8 | 78 | YES | NO |
CVE-2021-21881CRITICAL An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can | Dec 22, 2021 | 9.9 | 63 | NO | YES |
CVE-2021-21892CRITICAL A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request ca | Dec 22, 2021 | 9.9 | 46 | NO | NO |
CVE-2025-70082CRITICAL An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component | Mar 11, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-67035CRITICAL An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of inp | Mar 11, 2026 | 9.8 | 33 | NO | NO |
CVE-2021-21883CRITICAL An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead t | Dec 22, 2021 | 9.9 | 33 | NO | NO |
CVE-2025-67041CRITICAL An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to e | Mar 11, 2026 | 9.8 | 32 | NO | NO |
CVE-2021-21872CRITICAL An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can | Dec 22, 2021 | 9.9 | 32 | NO | NO |
CVE-2025-67039CRITICAL An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authori | Mar 11, 2026 | 9.1 | 31 | NO | NO |
CVE-2025-67034HIGH An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the managem | Mar 11, 2026 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lantronix.
Media articles that mention a CVE ID that affects a product developed by Lantronix — matched by CVE ID, not by vendor name.