CVE-2025-67038

Summary

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Affected Software

VendorProductVersion RangeStatus
LantronixEDS5000 series0 <= 2.1.0.0R3affected
LantronixEDS5000 series2.2.0.0R1unaffected
LantronixG520 series0 < 2.6.0.4R6affected
LantronixG520 series2.6.0.4R6unaffected
LantronixX300 series0 < 2.6.0.4R6affected
LantronixX300 series2.6.0.4R6unaffected
LantronixE210 series0 < 3.21.0.0R1affected
LantronixE210 series3.21.0.0R1unaffected
LantronixE220 series0 < 3.21.0.0R1affected
LantronixE220 series3.21.0.0R1unaffected

Weaknesses

  • CWE-78: CWE-78

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References