Impact
The vulnerability occurs in the HTTP RPC module of Lantronix EDS5000 firmware 2.1.0.0 R3, where a command used to write logs on authentication failure is built by concatenating the supplied username directly into a shell command without sanitization. This flaw (CWE‑94) permits an attacker to inject arbitrary OS commands into the username field, which are then executed with root privileges. Because the command runs with full administrative rights, the impact is complete system compromise and the ability to perform any action the root user can, including installing back‑doors, exfiltrating data, or disrupting services.
Affected Systems
Affected products are Lantronix EDS5000 series devices, including the EDS5008, EDS5016, and EDS5032 models, all running firmware version 2.1.0.0 R3.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of 16% signals a higher likelihood that this vulnerability will be attacked in the wild. The CVE is listed in the CISA KEV catalog, confirming it is a known active threat. The attack vector is inferred to be network‑based, since the vulnerable interface is reachable over HTTP RPC; a remote attacker can craft a username containing shell commands, trigger a failed authentication, and have those commands executed as root. The lack of a known public exploit does not mitigate the risk, as the described attack path is straightforward and does not require additional privileged access.
OpenCVE Enrichment