Open Menu

Software

Lantronix Centralized Management Software

Services

Services

Resources

From training , to white papers, videos, and more, you’ll find what you need to design, develop, deploy and manage powerful, innovative remote networking and IT infrastructure management applications and solutions.

Security Matters

Cyber Resilience & How to Report a Security Vulnerability

Security Updates, Vulnerability Disclosure Policy & Reporting 

Our Commitment to Product Security

Lantronix is committed to protecting our customers through secure product design and proactive vulnerability management. Consistent with Cyber Resilience Act (CRA), we engage with customers, partners, and security researchers to identify, evaluate, and remediate CVEs through coordinated disclosure practices. Through timely security updates, firmware releases, software patches, and technical support, we are dedicated to expediting the resolution of CVEs and reducing cybersecurity risk throughout the product lifecycle.

How to Report a Security Vulnerability

If you have identified a potential security vulnerability in a Lantronix product or would like the status of a known issue (for example, a CVE), please use the secure form below.

Researchers may also report through CERT/CC’s Vulnerability Information and Coordination Environment (VINCE), a coordinated disclosure platform on which Lantronix is a registered vendor.

Please avoid including sensitive personal or customer data in your report. Refer to the Privacy note below.

Security Advisories

Lantronix’s vulnerability disclosure and remediation practices are intended to align with recognized cybersecurity governance and compliance frameworks, including CISA’s Coordinated Vulnerability Disclosure Program, the European Union Cyber Resilience Act, and the CVE Program. These frameworks support documented intake, assessment, coordination, tracking, remediation, and public disclosure of cybersecurity vulnerabilities. Lantronix works to maintain processes that enable responsible coordination with affected stakeholders, including customers, partners, service providers, vendors, and security researchers, while supporting consistent CVE identification and lifecycle-based risk management for products with digital elements.

References: https://www.cisa.gov/resources-tools/programs/coordinated-vulnerability-disclosure-program; https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act; https://www.cve.org/

Software Security Update & Support Period

Lantronix provides periodic software updates to address security vulnerabilities and other identified issues for the duration of a product’s active support life.

Products remain eligible for security updates until they reach their End of Software Maintenance (EoSM) date, as specified in the Product Discontinuation Notice (PDN) issued at the start of that product’s end-of-life period.

Privacy

When submitting a report, please refrain from including sensitive personal information about yourself or your customers. Lantronix is committed to protecting the confidentiality of information you provide and adheres strictly to data protection guidelines to safeguard your data

Version 3.0 – August 2026

Disclaimer: Lantronix reserves the right to revise this policy at any time without prior notice. The most current version will always be available on our website. By reporting a vulnerability, you agree to the terms set forth in this policy.

Questions?

If you have a question about this policy or about a specific product, contact us.

Software

Lantronix Centralized Management Software

Services

Services

Resources

From training , to white papers, videos, and more, you’ll find what you need to design, develop, deploy and manage powerful, innovative remote networking and IT infrastructure management applications and solutions.