Junglewise Threat Intelligence

CVE-2025-67036: Lantronix EDS5000 OS command injection in Log Info page

CVE-2025-67036 · Severity: high · CVSS 8.8 · Published 2026-03-11

Technologies: Lantronix Eds5016, Lantronix Eds5008 Firmware, Lantronix Eds5016 Firmware, Lantronix EDS5000 firmware, Lantronix Eds5032 Firmware, Lantronix Eds5008, Lantronix Eds5032. Vendors: Lantronix.

Executive brief

Lantronix EDS5000 is a series of enterprise-grade device servers used to connect and manage serial equipment over a network. A security flaw in the device's log management interface allows an authorized user to take full control of the system. By submitting a specially crafted file name, an attacker can execute administrative commands, potentially leading to data theft or complete disruption of the connected infrastructure.

Technical details

An OS command injection vulnerability exists in the Log Info page of Lantronix EDS5000 firmware version 2.1.0.0R3. The vulnerability is caused by a lack of input sanitization in the file name parameter used to retrieve log files. An authenticated attacker with network access to the management interface can inject shell metacharacters into this parameter to execute arbitrary OS commands with root-level privileges. While CISA-ADP initially reported a CVSS of 8.8, the specific ICSA-26-069-02 advisory for this CVE (CVE-2025-67036) lists a score of 7.2 due to the requirement for high-privilege authentication. Users are advised to upgrade to firmware version 2.2.0.0R1 or later to remediate the issue.

Affected products

  • Lantronix EDS5000 firmware 2.1.0.0R3
  • Lantronix EDS5008 2.1.0.0R3
  • Lantronix EDS5016 2.1.0.0R3
  • Lantronix EDS5032 2.1.0.0R3

Timeline

  • 2026-03-10: advisory: CISA ICSA-26-069-02 published
  • 2026-03-11: disclosed: CVE-2025-67036 published
  • 2026-03-11: patched: Firmware version 2.2.0.0R1 released

References

Related threats