CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Other sources
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix EDS5000to a version that resolves this vulnerability.Fixed in 2.2.0.0R1 - Upgrade
Upgrade
Lantronix E210 seriesto a version that resolves this vulnerability.Fixed in 3.21.0.0R1 - Upgrade
Upgrade
Lantronix E220 seriesto a version that resolves this vulnerability.Fixed in 3.21.0.0R1 - Upgrade
Upgrade
Lantronix G520 seriesto a version that resolves this vulnerability.Fixed in 2.6.0.4R6 - Upgrade
Upgrade
Lantronix X300 seriesto a version that resolves this vulnerability.Fixed in 2.6.0.4R6 - Compensating control
Evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines; for cloud services follow BOD 26-04 guidance, and discontinue use of the product if mitigations are unavailable.