CVE-2025-67036

HIGH

Lantronix EDS5000 2.1.0.0R3 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.

References (3)

Core 3
Core References
Various Sources
http://eds5000.com
Various Sources
http://lantronix.com
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
lantronix/eds5008_firmware 2.1.0.0 r3
lantronix/eds5016_firmware 2.1.0.0 r3
lantronix/eds5032_firmware 2.1.0.0 r3
Published Mar 11, 2026
Tracked Since Mar 12, 2026