NVD disclosure day

Published threat advisories for March 11, 2026

CVE advisoryCRITICAL

CVE-2025-66956

Asseco SEE Live Component Vulnerability Allows Remote Attachment Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in Asseco SEE Live's communication components allows remote attackers to access and execute attachments via computable URLs, potentially impacting confidentiality and integrity. This vulnerability, affecting Contact Plan, E-Mail, SMS, and Fax features, could lead to unauthorized code execution when user

CVE advisoryCRITICAL

CVE-2025-70082

Lantronix EDS3000PS Arbitrary Code Execution via ltrx_evo Component

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in Lantronix EDS devices, allowing unauthenticated network access for arbitrary code execution and sensitive information disclosure. Understanding the presence and network exposure of these devices is crucial for managing potential risks.

CVE advisoryCRITICAL

CVE-2025-67041

Lantronix EDS3000PS TFTP Host Parameter Allows Root Command Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Lantronix EDS3000PS devices allows an unauthenticated attacker to execute arbitrary commands with root privileges. The issue stems from improper sanitization of the TFTP client's host parameter in the Filesystem Browser page, enabling command injection. This could lead to complete device compromise a

CVE advisoryCRITICAL

CVE-2025-67039

Lantronix EDS3000PS Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A Lantronix device management vulnerability allows unauthenticated attackers to bypass authentication on management pages via URL manipulation and an Authorization header. This could lead to unauthorized access to sensitive device configurations and management functions. It is uncertain if this vulnerability is current

CVE advisoryKnown Exploit

CVE-2025-67038

Lantronix EDS5000 HTTP RPC Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in Lantronix EDS5000 devices, allowing unauthenticated attackers to execute arbitrary OS commands with root privileges through the HTTP RPC module by manipulating the username parameter. This could lead to a full compromise of affected devices.

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-67035

Lantronix EDS5000 OS Injection Vulnerability Allows Root Command Execution.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Multiple OS injection vulnerabilities exist in Lantronix EDS devices, allowing attackers to execute arbitrary commands with root privileges by injecting input into SSH pages. This could lead to full system compromise, affecting network-accessible infrastructure appliances used for serial device management. Readers shou