CVE-2025-67037: Code Injection
Published Mar 11, 2026
·Updated
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
Affected Software
7 affected components
Lantronix EDS5000
All of the following
Lantronix Eds5032 Firmware=2.1.0.0-r3
Lantronix Eds5032
All of the following
Lantronix Eds5008 Firmware=2.1.0.0-r3
Lantronix Eds5008
All of the following
Lantronix Eds5016 Firmware=2.1.0.0-r3
Lantronix Eds5016
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software