Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
Published: 2026-03-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

An OS injection vulnerability exists in the SSH Client and SSH Server pages of Lantronix EDS5000 firmware 2.1.0.0R3 due to missing sanitization of input parameters. The flaw allows an attacker to inject arbitrary shell commands into delete actions for objects such as server keys, users, and known hosts. Because the injected commands run with root privileges, the impact is Remote Code Execution. The weakness corresponds to CWE‑78 and CWE‑94, describing unchecked command execution.

Affected Systems

The vulnerability affects Lantronix EDS5008, EDS5016, and EDS5032 devices that are running firmware version 2.1.0.0R3. All three models share a common web-based management interface where the insecure SSH Client and SSH Server pages reside.

Risk and Exploitability

A CVSS v3.1 score of 8.6 indicates high severity, meaning the vulnerability can severely compromise confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA KEV, but the high CVSS still warrants attention. Based on the description, it is inferred that an attacker would need some form of access to the device and could use any valid input to the delete endpoints to execute arbitrary shell commands with root privileges.

Generated by OpenCVE AI on September 5, 2026 at 01:06 UTC.

Remediation

Vendor Solution

Latronix has released the following updates addressing these vulnerabilities. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).


OpenCVE Recommended Actions

  • Upgrade Lantronix EDS5000 firmware to version 2.2.0.0R1 or later, as released by the vendor to address input sanitization issues.
  • If a patch is not immediately available, disable or restrict access to the SSH Client and SSH Server web pages from untrusted networks.
  • Configure firewall rules or VLAN segmentation to limit management-interface traffic to trusted IP ranges.
  • Enable logging for delete operations and monitor for anomalous activity indicative of injected command execution.

Generated by OpenCVE AI on September 5, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title OS Injection Vulnerabilities in Lantronix EDS5000 SSH Client and Server Pages Allow Remote Command Execution with Root Privileges Lantronix EDS5000 OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Fri, 20 Mar 2026 14:45:00 +0000

Type Values Removed Values Added
Title OS Injection Vulnerabilities in Lantronix EDS5000 SSH Client and Server Pages Allow Remote Command Execution with Root Privileges

Thu, 19 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix eds5008
Lantronix eds5008 Firmware
Lantronix eds5016
Lantronix eds5016 Firmware
Lantronix eds5032
Lantronix eds5032 Firmware
CPEs cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0:r3:*:*:*:*:*:*
Vendors & Products Lantronix eds5008
Lantronix eds5008 Firmware
Lantronix eds5016
Lantronix eds5016 Firmware
Lantronix eds5032
Lantronix eds5032 Firmware

Fri, 13 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix
Lantronix eds5000
Vendors & Products Lantronix
Lantronix eds5000

Wed, 11 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
References

Subscriptions

Lantronix Eds5000 Eds5008 Eds5008 Firmware Eds5016 Eds5016 Firmware Eds5032 Eds5032 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T20:14:09.538Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67035

cve-icon Vulnrichment

Updated: 2026-03-12T14:33:34.617Z

cve-icon NVD

Status : Modified

Published: 2026-03-11T17:16:51.673

Modified: 2026-09-04T21:17:21.140

Link: CVE-2025-67035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T01:15:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')