An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLantronix Eds5008
HWLantronixall versionsLantronix Eds5008 Firmware
OSLantronix2.1.0.0r3Lantronix Eds5016
HWLantronixall versionsLantronix Eds5016 Firmware
OSLantronix2.1.0.0r3Lantronix Eds5032
HWLantronixall versionsLantronix Eds5032 Firmware
OSLantronix2.1.0.0r3
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
Related vulnerabilities
CVE-2025-67038CRITICAL9.3⚠ KEVsame product
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write ...
CVE-2025-67035HIGH8.6PL ✓same product
OS command injection w Lantronix EDS5000 — wykonanie kodu jako root
CVE-2025-67036HIGH8.6same product
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by spe...
CVE-2025-67037HIGH8.6same product
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into ...
CVE-2025-67039CRITICAL9.3PL ✓same vendor
Pominięcie uwierzytelnienia w urządzeniach Lantronix EDS3000PS