An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
History

Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix
Lantronix eds5000
Vendors & Products Lantronix
Lantronix eds5000

Wed, 11 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-03-11T00:00:00.000Z

Updated: 2026-03-12T14:38:53.579Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67036

cve-icon Vulnrichment

Updated: 2026-03-12T14:35:51.637Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-11T17:16:51.790

Modified: 2026-03-12T21:08:22.643

Link: CVE-2025-67036

cve-icon Redhat

No data.