CVE-2025-67038
9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ics-cert@hq.dhs.gov (Secondary)
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Affected (33)
Products: Lantronix: Eds5008 Firmware, Eds5016 Firmware, Eds5032 Firmware, G526gp12s Firmware, G526gp17s Firmware, G526gp1cs Firmware, G526gp1asg Firmware, G526gp1as Firmware, G527gp22s Firmware, G527gp27s Firmware, G527gp2as Firmware, G527gp2asg Firmware, G528gp2fs Firmware, G528gp2fsg Firmware, G528gp2fsgc Firmware, X300f202s Firmware, X303f202s Firmware, X304g00as Firmware, X304g000s Firmware, X304g002s Firmware, X304g007s Firmware, X304g00cs Firmware, E228g002s Firmware, E228g004s Firmware, E228g00cb28 Firmware, E228g00cs Firmware, E213f102s Firmware, E214f002s Firmware, E214f00cs Firmware, E214g000s Firmware, E214g001s Firmware, E218f004s Firmware, E218g107s Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.0.0r1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix Eds5008 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.0.0r1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix Eds5016 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2.0.0r1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix Eds5032 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G526gp12s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G526gp17s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G526gp1cs | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G526gp1asg | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G526gp1as | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G527gp22s | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G527gp27s | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G527gp2as | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G527gp2asg | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G528gp2fs | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G528gp2fsg | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix G528gp2fsgc | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X300f202s | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X303f202s | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X304g00as | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X304g000s | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X304g002s | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X304g007s | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.6.0.4R6 |
| Running on/with | Platform Versions |
|---|---|
Lantronix X304g00cs | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E228g002s | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E228g004s | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E228g00cb28 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E228g00cs | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E213f102s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E214f002s | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E214f00cs | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E214g000s | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E214g001s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E218f004s | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.21.0.0R1 |
| Running on/with | Platform Versions |
|---|---|
Lantronix E218g107s | All versions |
Related CWEs
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-94
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References (4)
Source: ics-cert@hq.dhs.gov
Third Party Advisory
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryVDB Entry
Source: ics-cert@hq.dhs.gov
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.