Database/Control plane, storage & DevOps

Lantronix xPrintServer: The device ships with a hardcoded root account baked into every unit of a given firmware line
Impact
The device ships with a hardcoded root account baked into every unit of a given firmware line. Anyone who can reach the management interface gets root on the box without needing to guess or phish a credential — it's the same key for every deployed unit.
Who can reach it
No authentication needed beyond network reachability to the device; the credential is embedded in firmware and identical across all units running the affected build.
What to do
Firmware flash to 5.0.1-65 or later on every affected unit — this isn't something a config change or password rotation fixes, since the account is compiled into the image. Budget one flash-and-reboot cycle per device; xPrintServer's main job (serial/print bridging) is unavailable during the flash.
References
Related entries
- HPE iLO3 / iLO4: Multiple unspecified flaws allowing remote information disclosure, data modification and DoSCVE-2016-4375 · HPE iLO3 / iLO4Critical
- Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) framework: Log into the Niagara platform with a disabled account nameCVE-2017-16748 · Tridium Niagara AX (<=3.8) and Niagara 4 (<=4.4) frameworkCritical
- Lenovo / IBM Integrated Management Module 2 (IMM2) web administration service: The overflow is inside theCVE-2017-3774 · Lenovo / IBM Integrated Management Module 2 (IMM2) web administration serviceCritical
- Intel Active Management Technology / Standard Manageability: An authentication bypass in the AMT web interface: sendingCVE-2017-5689 · Intel Active Management Technology / Standard ManageabilityCritical
- HPE iLO2: Authentication bypass and code execution in iLO2 firmware 2.29CVE-2017-8979 · HPE iLO2Critical
- ntpq / ntpdc (NTP 4.2.8p11 client utilities): Stack buffer overflow in the ntpq and ntpdc command-line tools via a longCVE-2018-12327 · ntpq / ntpdc (NTP 4.2.8p11 client utilities)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.