Latest Lantronix vulnerabilities: Xport #

On April 15, 2025, CISA published an advisory announcing that certain versions of the Lantronix Xport products are affected by an authentication bypass vulnerability.

This vulnerability has been designated CVE-2025-2567 and has been assigned a CVSS score of 9.8 (critical).

What is the impact? #

Successfully exploiting this vulnerability could allow an attacker unauthorized access to the configuration interface, leading to potential disruption to monitoring and operations.

Xport versions 6.5.0.7 through 7.0.0.3 are vulnerable.

Are updates or workarounds available? #

Lantronix recommends that users upgrade to their Xport Edge product, which is not affected by this vulnerability. 

As a mitigation, the general recommendation is to limit network exposure for all control systems and devices. In general control systems and devices shouldn't be directly connected to the public internet. In most cases they're not designed with security in mind and depend on another edge device.

How do I find potentially vulnerable systems with runZero? #

From the Asset Inventory, use the following query to locate potentially vulnerable systems:

hw:lantronix AND ((os:="Lantronix XPort%" AND not os:="Lantronix XPort Edge%") OR (lantronix.type:="XE" OR lantronix.type:="SE" OR lantronix.type:="AR" OR lantronix.type:="EH"))

Written by runZero Team

Great research and development is a team effort! Multiple runZero team members collaborated on this post. Go team!

More about runZero Team
Subscribe Now

Get the latest news and expert insights delivered in your inbox.

Welcome to the club! Your subscription to our newsletter is successful.


Explore more

Webcasts
The Unreasonable Effectiveness of Inside Out Attack Surface Management
HD Moore, founder of runZero (and previously Metasploit), presents new research that will forever redefine how you approach attack surface...
Webcasts
Safeguarding OT/ICS Assets: Insights from the U.S. Department of Energy
Security experts from the National Renewable Energy Lab’s (NREL) Clean Energy Cybersecurity Accelerator™ (CECA) program join runZero to discuss...
runZero Insights
Ensure compliance with DORA’s ICT risk framework using runZero
Learn how to uncover unmanaged and unknown assets— including IT, OT, and IoT— to meet DORA's hidden risk requirements using runZero.
Talks
DEF CON 32: SSHamble: Unexpected Exposures in SSH (Video)
This talk digs deep into SSH, the lesser-known implementations, many of the surprising security issues found along the way, and how to exploit them.

See Results in Minutes

See & secure your total attack surface. Even the unknowns & unmanageable.

Discover the new era of exposure management!