← Back

CVE-2025-67038

nvd nist
Published: Mar 11, 2026Modified: Jul 6, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Affected (3)

3 products
Eds5032 Firmware
Eds5008 Firmware
Eds5016 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5032
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5008
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.1.0.0r3
Running on/withPlatform Versions
Lantronix
Eds5016
All versions

References (2)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.