← Back

CVE-2025-67041

nvd nist
Published: Mar 11, 2026Modified: Jul 5, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.

Affected (2)

2 products
Eds3016ps1ns Firmware
Eds3008ps1ns Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.1.0.0r2
Running on/withPlatform Versions
Lantronix
Eds3016ps1ns
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.1.0.0r2
Running on/withPlatform Versions
Lantronix
Eds3008ps1ns
All versions

References (1)

Source: cve@mitre.org
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.