216.73.217.22

CVE-2025-67038

· Published 11/03/2026 17:16 · Modified 12/03/2026 21:08

Labels: CVE-2025-67038 2026-03-11CVE-2025-67038CWE-94[email protected]

Essential information

Published
11/03/2026 17:16
Modified
12/03/2026 21:08
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
lantronix / eds5000 cpe:2.3:a:lantronix:eds5000:2.1.0.0R3:*:*:*:*:*:*:*

References