Lantronix EDS3000PS OS Command Injection
Summary
| CVE | CVE-2025-67041 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-11 17:16:52 UTC |
| Updated | 2026-09-04 21:17:23 UTC |
| Description | An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges. |
Risk And Classification
Primary CVSS: v4.0 8.6 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.004170000 probability, percentile 0.348970000 (date 2026-09-07)
Problem Types: CWE-78 | CWE-288 | CWE-620 | CWE-78 CWE-78 | CWE-78 CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CWE-288 CWE-288 Authentication Bypass Using an Alternate Path or Channel | CWE-620 CWE-620 Unverified Password Change
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.6 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| 3.1 | ADP | DECLARED | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.2 | HIGH | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lantronix | Eds3008ps1ns | - | All | All | All |
| Operating System | Lantronix | Eds3008ps1ns Firmware | 3.1.0.0r2 | All | All | All |
| Hardware | Lantronix | Eds3016ps1ns | - | All | All | All |
| Operating System | Lantronix | Eds3016ps1ns Firmware | 3.1.0.0r2 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Lantronix | EDS3000PS Series | affected 3.1.0.0R2 custom | Not specified |
| CNA | Lantronix | EDS3000PS Series | unaffected 3.2.0.0R2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-p... | [email protected] | www.lantronix.com | |
| github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-06... | [email protected] | github.com | |
| www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 | [email protected] | www.cisa.gov | Third Party Advisory, US Government Resource |
| eds3000ps.com | MITRE | eds3000ps.com | |
| lantronix.com | MITRE | lantronix.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS3000PS series to CISA. (en)
Additional Advisory Data
Solutions
CNA: Latronix has released the following updates addressing this vulnerability. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).
CNA: EDS3000PS series: Upgrade to version 3.2.0.0R2 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1349189633/Latest+Firmware+for+the+EDS3000PS+series
CNA: For more information or technical assistance, contact Lantronix support ([email protected]). mailto:[email protected]