Vulnerabilities > Lantronix > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-23 CVE-2023-7237 Inadequate Encryption Strength vulnerability in Lantronix Xport Edge Firmware 2.0.0.13
Lantronix XPort sends weakly encoded credentials within web request headers.
network
low complexity
lantronix CWE-326
7.5
2021-12-22 CVE-2021-21879 Path Traversal vulnerability in Lantronix Premierwave 2050 8.9.0.0
A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
8.8
2021-12-22 CVE-2021-21880 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
7.2
2021-12-22 CVE-2021-21882 OS Command Injection vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-78
8.8
2021-12-22 CVE-2021-21885 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4.
network
low complexity
lantronix CWE-22
7.2
2021-12-22 CVE-2021-21895 Path Traversal vulnerability in Lantronix Premierwave 2050 Firmware 8.9.0.0
A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU).
network
low complexity
lantronix CWE-22
7.2