PT-2025-30497 · Lantronix · Lantronix Provisioning Manager

Published

2025-07-22

·

Updated

2025-07-23

·

CVE-2025-7766

CVSS v3.1
8.0
VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Lantronix Provisioning Manager (affected versions not specified)

Description:

Lantronix Provisioning Manager is susceptible to XML external entity attacks through configuration files received from network devices. Successful exploitation can result in unauthenticated remote code execution on systems where Provisioning Manager is installed.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-7766

Affected Products

Lantronix Provisioning Manager