CVE-2025-67037

Summary

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.

Affected Software

VendorProductVersion RangeStatus
LantronixEDS5000 series0 <= 2.1.0.0R3affected
LantronixEDS5000 series2.2.0.0R1unaffected
LantronixG520 series0 < 2.6.0.4R6affected
LantronixG520 series2.6.0.4R6unaffected
LantronixX300 series0 < 2.6.0.4R6affected
LantronixX300 series2.6.0.4R6unaffected

Weaknesses

  • CWE-78: CWE-78

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References