Lantronix Provisioning Manager Unauthenticated Remote Code Execution Vulnerability via XML External Entity Attack
Vulnerability
A vulnerability in Lantronix Provisioning Manager versions through 7.10.2 allows for unauthenticated remote code execution. This issue arises from improper handling of XML external entity references in configuration files provided by network devices, creating a risk of XML external entity (XXE) attacks.
Impact
Exploitation of this vulnerability could lead to unauthorized remote code execution on the host where Lantronix Provisioning Manager is installed.
Remediation
Users are advised to update Lantronix Provisioning Manager to version 7.10.4 or later.
Added: Jul 22, 2025, 10:20 PM
Updated: Jul 22, 2025, 10:20 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
7.4remediation
7.7relevance
0.3threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
