CVE-2025-67036: Lantronix EDS5000, G520, and X300 OS Command Injection
Published Mar 11, 2026
·Updated
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
Affected Software
7 affected components
Lantronix EDS5000
All of the following
Lantronix Eds5032 Firmware=2.1.0.0r3
Lantronix Eds5032
All of the following
Lantronix Eds5008 Firmware=2.1.0.0r3
Lantronix Eds5008
All of the following
Lantronix Eds5016 Firmware=2.1.0.0r3
Lantronix Eds5016
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix EDS5000to a version that resolves this vulnerability.Fixed in 2.2.0.0R1 - Upgrade
Upgrade
Lantronix G520 seriesto a version that resolves this vulnerability.Fixed in 2.6.0.4R6 - Upgrade
Upgrade
Lantronix X300 seriesto a version that resolves this vulnerability.Fixed in 2.6.0.4R6
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software