Impact
An OS injection vulnerability exists in the SSH Client and SSH Server pages of Lantronix EDS5000 firmware 2.1.0.0R3 due to missing sanitization of input parameters. The flaw allows an attacker to inject arbitrary shell commands into delete actions for objects such as server keys, users, and known hosts. Because the injected commands run with root privileges, the impact is Remote Code Execution. The weakness corresponds to CWE‑78 and CWE‑94, describing unchecked command execution.
Affected Systems
The vulnerability affects Lantronix EDS5008, EDS5016, and EDS5032 devices that are running firmware version 2.1.0.0R3. All three models share a common web-based management interface where the insecure SSH Client and SSH Server pages reside.
Risk and Exploitability
A CVSS v3.1 score of 8.6 indicates high severity, meaning the vulnerability can severely compromise confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA KEV, but the high CVSS still warrants attention. Based on the description, it is inferred that an attacker would need some form of access to the device and could use any valid input to the delete endpoints to execute arbitrary shell commands with root privileges.
OpenCVE Enrichment