Overview
The Lantronix xPrintServer and its accompanying cloud storage API contains several vulnerabilities.
Description
| CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') - CVE-2014-9002 An unauthenticated attacker can include a shell command inside the 'c' parameter of an AJAX request to the device, which is then executed in context of the device root. According to Lantronix, this issue was addressed in version 3.3.0. | 
Impact
| An unauthenticated remote attacker may be able to learn private information about the device's internal network, access or modify the device's configuration or files, or gain root access to the device. | 
Solution
| Apply an update | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | 8.3 | AV:A/AC:L/Au:N/C:C/I:C/A:C | 
| Temporal | 6.5 | E:POC/RL:OF/RC:C | 
| Environmental | 4.9 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND | 
References
Acknowledgements
Thanks to the reporter who wishes to remain anonymous.
This document was written by Garret Wassermann.
Other Information
| CVE IDs: | CVE-2014-9002, CVE-2014-9003, CVE-2016-4325 | 
| Date Public: | 2016-05-13 | 
| Date First Published: | 2016-05-13 | 
| Date Last Updated: | 2016-05-13 22:43 UTC | 
| Document Revision: | 40 |