Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
Published: 2026-03-11
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Lantronix devices running the EDS5000 firmware series expose a Log Info page that accepts a file name parameter. The vendor’s implementation fails to sanitize that parameter, allowing an authenticated user to supply a string that is interpreted as an operating‑system command, which is then executed with root privileges. This flaw chain provides the attacker full control over the device’s underlying OS, giving complete compromise of confidentiality, integrity, and availability. The vulnerability is aligned with CWE‑94 (Improper Control of Generation of Code) and CWE‑78 (OS Command Injection).

Affected Systems

The problem appears in Lantronix EDS5000 devices carrying firmware version 2.1.0.0 R3, affecting the EDS5008, EDS5016, and EDS5032 product lines. Related G520 and X300 series devices are also part of the affected inventory, and pending updates from Lantronix target these series. The Log Info page is accessible only after authentication, so only users who can log in and navigate that page can trigger the vulnerability, but those credentials enable execution of arbitrary commands as root.

Risk and Exploitability

The CVSS score of 8.6 classifies the flaw as High severity. An EPSS score of less than 1 % indicates that active exploitation is currently rare. The issue is not listed in the CISA KEV catalog. Although exploitation requires valid credentials, the audited attack steps are straightforward once those credentials are obtained, providing uncontested OS command execution at the highest privilege level.

Generated by OpenCVE AI on September 5, 2026 at 00:38 UTC.

Remediation

Vendor Solution

Latronix has released the following updates addressing this vulnerability. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).


OpenCVE Recommended Actions

  • Update your device firmware to the latest release as recommended by Lantronix—EDS5000 firmware 2.2.0.0 R1 or newer, G520 firmware 2.6.0.4 R6 or newer, and X300 firmware 2.6.0.4 R6 or newer—by downloading the official patches from Lantronix’s support site.
  • Re‑configure the device to restrict access to the Log Info page, allowing it only for essential administrators or by disabling the page entirely if the function is unnecessary.
  • Apply a firewall rule to block external access to the Log Info page URL (/loginfo) so only internal management traffic can reach it.

Generated by OpenCVE AI on September 5, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Lantronix EDS5000, G520, and X300 OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Thu, 19 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix eds5008
Lantronix eds5008 Firmware
Lantronix eds5016
Lantronix eds5016 Firmware
Lantronix eds5032
Lantronix eds5032 Firmware
CPEs cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0:r3:*:*:*:*:*:*
Vendors & Products Lantronix eds5008
Lantronix eds5008 Firmware
Lantronix eds5016
Lantronix eds5016 Firmware
Lantronix eds5032
Lantronix eds5032 Firmware

Thu, 12 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Lantronix
Lantronix eds5000
Vendors & Products Lantronix
Lantronix eds5000

Wed, 11 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
References

Subscriptions

Lantronix Eds5000 Eds5008 Eds5008 Firmware Eds5016 Eds5016 Firmware Eds5032 Eds5032 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-04T20:19:40.179Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67036

cve-icon Vulnrichment

Updated: 2026-03-12T14:35:51.637Z

cve-icon NVD

Status : Modified

Published: 2026-03-11T17:16:51.790

Modified: 2026-09-04T21:17:21.647

Link: CVE-2025-67036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:45:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')