Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lantronix

First CVE: Jul 11, 2005Active for: 21 yearsTotal CVEs: 43
61.3
VTI Score
TOP TARGET

Lantronix manufactures a focused line of remote access and serial communication appliances, notably the PremierWave and EDS product families, that serve industrial and enterprise environments where they often bridge legacy systems to modern networks. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur persistently across its firmware and device interfaces through command injection, path traversal, code injection, and memory-safety weaknesses that are characteristic of embedded appliances with limited update cadence. These weakness classes reflect the parsing and privilege-boundary challenges inherent to devices that handle untrusted input from multiple network interfaces and must execute administrative functions. Defenders should prioritize inventory and network isolation of affected Lantronix devices, since the vendor's narrow but strategically positioned product line means that patching cycles and firmware updates may lag behind disclosure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
43
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
2.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Lantronix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 11, 2005
21 years ago
Most Recent CVE
Mar 11, 2026
135 days ago

Products(25 total)

Top CVEs

Signals from CVEs in this vendor scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-67038CRITICAL
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concat
Mar 11, 20269.878YESNO
CVE-2021-21881CRITICAL
An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can
Dec 22, 20219.963NOYES
CVE-2021-21892CRITICAL
A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request ca
Dec 22, 20219.946NONO
CVE-2025-70082CRITICAL
An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive information via the ltrx_evo component
Mar 11, 20269.833NONO
CVE-2025-67035CRITICAL
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of inp
Mar 11, 20269.833NONO
CVE-2021-21883CRITICAL
An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead t
Dec 22, 20219.933NONO
CVE-2025-67041CRITICAL
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to e
Mar 11, 20269.832NONO
CVE-2021-21872CRITICAL
An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can
Dec 22, 20219.932NONO
CVE-2025-67039CRITICAL
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authori
Mar 11, 20269.131NONO
CVE-2025-67034HIGH
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the managem
Mar 11, 20268.831NONO
View all 43 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products43 CVEs
19%
26%
53%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (88.4%)
Unknown5 (11.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (86.0%)
High1 (2.3%)
Unknown5 (11.6%)
User Interaction
None35 (81.4%)
Unknown5 (11.6%)
Required3 (7.0%)
Privileges Required
Low11 (25.6%)
High17 (39.5%)
None10 (23.3%)
Unknown5 (11.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (43 CVEs).

CISA KEV
1 CVE
2.3% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
4.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lantronix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lantronix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lantronix's Products

View all 4 CNAs →

Top CWEs