Executive brief
Lantronix EDS5000 series devices, which are used to connect and manage industrial equipment over a network, contain a security flaw in their management interface. An authorized user can send a specially crafted request while deleting security credentials to take full control of the device. This could allow an attacker to disrupt industrial operations, intercept sensitive data, or use the device as a foothold to attack other parts of the corporate network.
Technical details
An OS command injection vulnerability exists in the Lantronix EDS5000 firmware version 2.1.0.0R3. The flaw is located within the management interface's SSL credential deletion functionality, specifically due to improper sanitization of the 'name' parameter. An authenticated attacker with network access to the management interface can inject arbitrary shell commands that the system executes with root-level privileges. This vulnerability is tracked as CWE-94/CWE-78. Lantronix has released firmware version 2.2.0.0R1 to address this and several other related injection vulnerabilities.
Affected products
- Lantronix EDS5000 firmware 2.1.0.0R3
- Lantronix EDS5008 2.1.0.0R3
- Lantronix EDS5016 2.1.0.0R3
- Lantronix EDS5032 2.1.0.0R3
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE-2025-67034 published to NVD
- 2026-03-11: patched: Lantronix released firmware version 2.2.0.0R1 to address the issue