Impact
Lantronix devices running the EDS5000 firmware series expose a Log Info page that accepts a file name parameter. The vendor’s implementation fails to sanitize that parameter, allowing an authenticated user to supply a string that is interpreted as an operating‑system command, which is then executed with root privileges. This flaw chain provides the attacker full control over the device’s underlying OS, giving complete compromise of confidentiality, integrity, and availability. The vulnerability is aligned with CWE‑94 (Improper Control of Generation of Code) and CWE‑78 (OS Command Injection).
Affected Systems
The problem appears in Lantronix EDS5000 devices carrying firmware version 2.1.0.0 R3, affecting the EDS5008, EDS5016, and EDS5032 product lines. Related G520 and X300 series devices are also part of the affected inventory, and pending updates from Lantronix target these series. The Log Info page is accessible only after authentication, so only users who can log in and navigate that page can trigger the vulnerability, but those credentials enable execution of arbitrary commands as root.
Risk and Exploitability
The CVSS score of 8.6 classifies the flaw as High severity. An EPSS score of less than 1 % indicates that active exploitation is currently rare. The issue is not listed in the CISA KEV catalog. Although exploitation requires valid credentials, the audited attack steps are straightforward once those credentials are obtained, providing uncontested OS command execution at the highest privilege level.
OpenCVE Enrichment