Database/Control plane, storage & DevOps

Lantronix EDS3000PS serial-to-Ethernet device server: Full bypass of the management-page login
Impact
Full bypass of the management-page login. Appending a specific suffix to a management URL, combined with a crafted Authorization header, gets an attacker straight into admin functionality with no valid credentials — including whatever serial console sessions the device is bridging.
Who can reach it
Purely network-based, no credentials required — the attacker just needs to reach the device's web management port and knows the URL/header trick published in the advisory.
What to do
Firmware flash to the fixed release; this is an auth-check logic bug, not something you can compensate for with a password change. Roll out per device; each flash briefly interrupts the serial bridging that device provides.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.