CVE-2025-67034

Summary

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

Affected Software

VendorProductVersion RangeStatus
LantronixEDS5000 series0 <= 2.1.0.0R3affected
LantronixEDS5000 series2.2.0.0R1unaffected
LantronixG520 series0 < 2.6.0.4R6affected
LantronixG520 series2.6.0.4R6unaffected
LantronixX300 series0 < 2.6.0.4R6affected
LantronixX300 series2.6.0.4R6unaffected

Weaknesses

  • CWE-78: CWE-78

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References