CVE-2025-67036

Summary

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.

Affected Software

VendorProductVersion RangeStatus
LantronixEDS5000 series0 <= 2.1.0.0R3affected
LantronixEDS5000 series2.2.0.0R1unaffected
LantronixG520 series0 < 2.6.0.4R6affected
LantronixG520 series2.6.0.4R6unaffected
LantronixX300 series0 < 2.6.0.4R6affected
LantronixX300 series2.6.0.4R6unaffected

Weaknesses

  • CWE-78: CWE-78

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References