Questions?
If you have a question about this policy or about a specific product, contact us.
| Severity | Advisory | CVE(s) | Affected Products | Publish Date | View Advisory |
|---|---|---|---|---|---|
| Low | X300 Series Firmware Update |
CVE-2025-67034
CVE-2025-67036
CVE-2025-67037
CVE-2025-67038
|
June 29, 2026 | Learn More | |
| Low | G520 Series Firmware Update |
CVE-2025-67034
CVE-2025-67036
CVE-2025-67037
CVE-2025-67038
|
June 29, 2026 | Learn More | |
| Low | E210 and E220 Series Firmware Update |
CVE-2025-67038
|
June 29, 2026 | Learn More | |
| Low | EDS5000 Firmware Update | June 26, 2026 | Learn More |
Lantronix is committed to protecting our customers through secure product design and proactive vulnerability management. Consistent with Cyber Resilience Act (CRA), we engage with customers, partners, and security researchers to identify, evaluate, and remediate CVEs through coordinated disclosure practices. Through timely security updates, firmware releases, software patches, and technical support, we are dedicated to expediting the resolution of CVEs and reducing cybersecurity risk throughout the product lifecycle.
If you have identified a potential security vulnerability in a Lantronix product or would like the status of a known issue (for example, a CVE), please use the secure form below.
Researchers may also report through CERT/CC’s Vulnerability Information and Coordination Environment (VINCE), a coordinated disclosure platform on which Lantronix is a registered vendor.
Please avoid including sensitive personal or customer data in your report. Refer to the Privacy policy.
Lantronix’s vulnerability disclosure and remediation practices are intended to align with recognized cybersecurity governance and compliance frameworks, including CISA’s Coordinated Vulnerability Disclosure Program, the European Union Cyber Resilience Act, and the CVE Program. These frameworks support documented intake, assessment, coordination, tracking, remediation, and public disclosure of cybersecurity vulnerabilities. Lantronix works to maintain processes that enable responsible coordination with affected stakeholders, including customers, partners, service providers, vendors, and security researchers, while supporting consistent CVE identification and lifecycle-based risk management for products with digital elements.
References: https://www.cisa.gov/resources-tools/programs/coordinated-vulnerability-disclosure-program; https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act; https://www.cve.org/
If you have a question about this policy or about a specific product, contact us.