An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
References
| Link | Resource |
|---|---|
| http://eds5000.com | Not Applicable |
| http://lantronix.com | Product |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2026-03-11 17:16
Updated : 2026-03-19 20:15
NVD link : CVE-2025-67036
Mitre link : CVE-2025-67036
CVE.ORG link : CVE-2025-67036
JSON object : View
Products Affected
lantronix
- eds5032_firmware
- eds5008_firmware
- eds5032
- eds5016
- eds5008
- eds5016_firmware
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
