← Back

CVE-2025-67036

nvd nist
Published: Mar 11, 2026Modified: Jul 5, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.

Affected (3)

3 products
Eds5032 Firmware
Eds5008 Firmware
Eds5016 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5032
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5008
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5016
All versions

References (1)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.