CVE-2025-2567 PUBLISHED

Lantronix Xport Missing Authentication for Critical Function

Assigner: icscert
Reserved: 20.03.2025 Published: 15.04.2025 Updated: 15.04.2025

An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling of ATG monitoring. This would result in potential safety hazards in fuel storage and transportation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Lantronix
Product Xport
Versions Default: unaffected
  • affected from 6.5.0.7 to 7.0.0.3 (incl.)

Workarounds

Lantronix recommends users upgrade to their Xport Edge product, which brings in more cutting edge security suite. Xport edge is not affected by these vulnerabilities. Users should contact Lantronix directly for assistance.

Credits

  • Souvik Kandar from Microsec(microsec.io) reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-306 CWE