Command Injection Vulnerability in Lantronix EDS5000
CVE-2025-67036
8.6HIGH
What is CVE-2025-67036?
A command injection vulnerability exists in the Lantronix EDS5000 where users can view log files by specifying file names. Due to inadequate sanitization of user input in the file name parameter, an authenticated attacker could potentially execute arbitrary operating system commands with root privileges, posing significant security risks. Users are advised to mitigate this vulnerability by applying vendor-provided patches and enforcing strict access controls.
Affected Version(s)
EDS5000 series 0 <= 2.1.0.0R3
G520 series 0 < 2.6.0.4R6
X300 series 0 < 2.6.0.4R6
