Lantronix EDS3000PS and EDS5000 OS Command Injection
Summary
| CVE | CVE-2025-67034 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-11 17:16:50 UTC |
| Updated | 2026-09-04 20:17:22 UTC |
| Description | An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges. |
Risk And Classification
Primary CVSS: v4.0 8.6 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004960000 probability, percentile 0.407990000 (date 2026-09-07)
Problem Types: CWE-78 | CWE-94 | CWE-78 CWE-78 | CWE-94 CWE-94 Improper Control of Generation of Code ('Code Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | ADP | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lantronix | Eds5008 | - | All | All | All |
| Operating System | Lantronix | Eds5008 Firmware | 2.1.0.0r3 | All | All | All |
| Hardware | Lantronix | Eds5016 | - | All | All | All |
| Operating System | Lantronix | Eds5016 Firmware | 2.1.0.0r3 | All | All | All |
| Hardware | Lantronix | Eds5032 | - | All | All | All |
| Operating System | Lantronix | Eds5032 Firmware | 2.1.0.0r3 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lantronix | EDS5000 Series | affected 2.1.0.0R3 custom | Not specified |
| CNA | Lantronix | EDS5000 Series | unaffected 2.2.0.0R1 | Not specified |
| CNA | Lantronix | G520 Series | affected 2.6.0.4R6 custom | Not specified |
| CNA | Lantronix | G520 Series | unaffected 2.6.0.4R6 | Not specified |
| CNA | Lantronix | X300 Series | affected 2.6.0.4R6 custom | Not specified |
| CNA | Lantronix | X300 Series | unaffected 2.6.0.4R6 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-p... | [email protected] | www.lantronix.com | |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-06... | [email protected] | github.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 | [email protected] | www.cisa.gov | Third Party Advisory, US Government Resource |
| eds5000.com | MITRE | eds5000.com | |
| lantronix.com | MITRE | lantronix.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerabilities for the EDS5000 series and EDS3000PS series to CISA. (en)
CNA: Lantronix reported the vulnerabilities for the G520 series, X300 series, E210 series, E220 series to CISA. (en)
Additional Advisory Data
Solutions
CNA: Latronix has released the following updates addressing these vulnerabilities. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).
CNA: EDS5000 series: Upgrade to version 2.2.0.0R1 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032
CNA: G520 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528
CNA: X300 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2135261185/Latest+firmware+for+the+X300+Series+X300+X303+X304
CNA: For more information or technical assistance, contact Lantronix support ([email protected]). mailto:[email protected]