GHSA-j94v-49mv-xq4hHighCVSS 8.8
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log...
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2025-67036
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- http://eds5000.com
- http://lantronix.com
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
- https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw
- https://github.com/advisories/GHSA-j94v-49mv-xq4h