CVE-2025-67037

HIGH

Lantronix EDS5000 2.1.0.0R3 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.

References (3)

Core 3
Core References
Various Sources
http://eds5000.com
Various Sources
http://lantronix.com
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 30.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
lantronix/eds5008_firmware 2.1.0.0 r3
lantronix/eds5016_firmware 2.1.0.0 r3
lantronix/eds5032_firmware 2.1.0.0 r3
Published Mar 11, 2026
Tracked Since Mar 12, 2026