Impact
The vulnerability occurs in the HTTP RPC module of Lantronix EDS5000 firmware 2.1.0.0R3, where a command used to write logs on authentication failure is built by concatenating the supplied username directly into a shell command without sanitization. A comparable issue exists in the G520, X300, E210, and E220 series. This flaw (CWE‑78) permits an attacker to inject arbitrary OS commands into the username field, which are then executed with root privileges. Because the command runs with full administrative rights, the impact is complete system compromise and the ability to perform any action the root user can, including installing back‑doors, exfiltrating data, or disrupting services. The CVSS score of 9.3 indicates a critical severity. The EPSS score of 19% signals a higher likelihood that this vulnerability will be attacked in the wild. The CVE is listed in the CISA KEV catalog, confirming it is a known active threat. The attack vector is inferred to be network‑based, since the vulnerable interface is reachable over HTTP RPC; a remote attacker can craft a username containing shell commands, trigger a failed authentication, and have those commands executed as root. The flaw affects multiple product lines, but the attack path remains the same and does not require additional privileged access.
Affected Systems
Affected products are Lantronix EDS5000, G520, X300, E210, and E220 series devices, including models EDS5008, EDS5016, EDS5032, G520, G526, G526RP, G527, G528, X300, X303, X304, E210, E213, E214, E215, E218, E220, E224, E225, E228, and the associated cellular router variants.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of 19% signals a higher likelihood that this vulnerability will be attacked in the wild. The CVE is listed in the CISA KEV catalog, confirming it is a known active threat. The attack vector is inferred to be network‑based, since the vulnerable interface is reachable over HTTP RPC; a remote attacker can craft a username containing shell commands, trigger a failed authentication, and have those commands executed as root. The flaw affects multiple product lines, but the attack path remains the same and does not require additional privileged access.
OpenCVE Enrichment