GHSA-w5v7-rqrc-ccv2HighCVSS 8.8
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS...
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2025-67037
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- http://eds5000.com
- http://lantronix.com
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
- https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw
- https://github.com/advisories/GHSA-w5v7-rqrc-ccv2