← Back

CVE-2025-67035

nvd nist
Published: Mar 11, 2026Modified: Jul 5, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.

Affected (3)

3 products
Eds5032 Firmware
Eds5008 Firmware
Eds5016 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5032
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5008
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5016
All versions

References (1)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.