OS Command Injection Vulnerability in Lantronix EDS5000
CVE-2025-67037
8.8HIGH
What is CVE-2025-67037?
A vulnerability exists in the Lantronix EDS5000, where an authenticated attacker can exploit the 'tunnel' parameter during a tunnel connection termination. This flaw allows attackers to inject OS commands that execute with root privileges, potentially compromising the integrity of the system. It is crucial for users of the EDS5000 to evaluate their exposure to this issue and apply necessary security updates to mitigate risks.
