CVE-2025-67035: Code Injection
Published Mar 11, 2026
·Updated
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
Affected Software
7 affected components
Lantronix EDS5000
All of the following
Lantronix Eds5032 Firmware=2.1.0.0r3
Lantronix Eds5032
All of the following
Lantronix Eds5008 Firmware=2.1.0.0r3
Lantronix Eds5008
All of the following
Lantronix Eds5016 Firmware=2.1.0.0r3
Lantronix Eds5016
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software