← Back

CVE-2025-67034

nvd nist
Published: Mar 11, 2026Modified: Jul 5, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

Affected (3)

3 products
Eds5032 Firmware
Eds5008 Firmware
Eds5016 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5032
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5008
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5016
All versions

References (1)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.