Executive brief
Lantronix EDS5000 series devices, which are used to connect and manage industrial equipment over a network, contain a security flaw in their SSH management interface. An attacker with administrative access can exploit this flaw to take full control of the device by executing unauthorized commands. This could lead to a complete compromise of the device, allowing an attacker to disrupt operations or access sensitive data within the industrial network.
Technical details
Multiple OS command injection vulnerabilities exist in the SSH Client and SSH Server management pages of Lantronix EDS5000 firmware version 2.1.0.0R3. The root cause is a failure to properly sanitize input parameters during 'delete' actions for objects such as server keys, users, and known hosts. An authenticated attacker with high privileges can inject arbitrary shell commands that are executed with root-level permissions. While CISA-ADP initially assigned a CVSS 9.8, the specific technical advisory for this CVE (CVE-2025-67035) indicates it requires authentication (PR:H), resulting in a CVSS 7.2. Users are advised to upgrade to firmware version 2.2.0.0R1 to remediate these issues.
Affected products
- Lantronix EDS5000 firmware 2.1.0.0R3
- Lantronix EDS5008 2.1.0.0R3
- Lantronix EDS5016 2.1.0.0R3
- Lantronix EDS5032 2.1.0.0R3
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE published in NVD
- 2026-03-11: patched: Vendor released firmware version 2.2.0.0R1