OS Injection Vulnerabilities in Lantronix EDS5000 Firmware
CVE-2025-67035
9.8CRITICAL
What is CVE-2025-67035?
A notable security issue has been detected in the Lantronix EDS5000 (version 2.1.0.0R3), impacting both the SSH Client and SSH Server functionalities. This vulnerability arises from inadequate sanitization of input parameters, allowing malicious actors to execute arbitrary commands during deletion actions relating to server keys, user accounts, and known hosts. The commands run with root privileges, thereby posing a significant risk to the device's integrity and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
