CVE-2025-67034

HIGH

Lantronix EDS5000 2.1.0.0R3 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

References (3)

Core 3
Core References
Various Sources
http://eds5000.com
Various Sources
http://lantronix.com
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02

Scores

CVSS v3 8.8
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
lantronix/eds5008_firmware 2.1.0.0 r3
lantronix/eds5016_firmware 2.1.0.0 r3
lantronix/eds5032_firmware 2.1.0.0 r3
Published Mar 11, 2026
Tracked Since Mar 12, 2026