CVE-2025-70082CRITICAL 2.7EPSS p37.6%
CVE-2025-70082CVE-2025-70082
lantronix / eds3016ps1ns_firmware
Description
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
Scoring
| CVSS 3.1 | 2.7 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.46% probability of exploitation · percentile 37.6% · 2026-10-05T12:00:23Z |
| Published | 2026-03-11 |
| Last modified | 2026-09-04 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass Using an Alternate Path or Channelcwe-288 | 0% | live |
| Weakness | Unverified Password Changecwe-620 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-78 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.