Lantronix EDS3000PS and EDS5000 Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Lantronix EDS3000PS version 3.1.0.0R2 and EDS5000 version 2.1.0.0R3. This vulnerability allows unauthorized access to management pages by appending a specific suffix to the URL and sending an Authorization header with 'admin' as the username.

Impact

Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access and actions within the application. According to CISA, successful exploitation could allow an attacker to execute code with root-level privileges.

Added: Mar 11, 2026, 5:33 PM
Updated: Mar 11, 2026, 5:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.6
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.