TELNET Access Vulnerability in Lantronix MSS Devices
CVE-2018-12925

9.8CRITICAL

Key Information:

Vendor

Lantronix

Vendor
CVE Published:
28 June 2018

What is CVE-2018-12925?

Lantronix MSS devices are susceptible to an authentication bypass vulnerability due to the lack of password requirements for TELNET access. This allows unauthorized users to easily access the device’s management interface, potentially compromising the security and integrity of the network. Administrators must take precautions to mitigate this vulnerability by ensuring that TELNET access is disabled or secured with appropriate firewall rules.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.