Executive brief
Lantronix EDS5000 is a series of enterprise-grade device servers used to connect and manage serial equipment over a network. A security flaw in the device's log management interface allows an authorized user to take full control of the system. By submitting a specially crafted file name, an attacker can execute administrative commands, potentially leading to data theft or complete disruption of the connected infrastructure.
Technical details
An OS command injection vulnerability exists in the Log Info page of Lantronix EDS5000 firmware version 2.1.0.0R3. The vulnerability is caused by a lack of input sanitization in the file name parameter used to retrieve log files. An authenticated attacker with network access to the management interface can inject shell metacharacters into this parameter to execute arbitrary OS commands with root-level privileges. While CISA-ADP initially reported a CVSS of 8.8, the specific ICSA-26-069-02 advisory for this CVE (CVE-2025-67036) lists a score of 7.2 due to the requirement for high-privilege authentication. Users are advised to upgrade to firmware version 2.2.0.0R1 or later to remediate the issue.
Affected products
- Lantronix EDS5000 firmware 2.1.0.0R3
- Lantronix EDS5008 2.1.0.0R3
- Lantronix EDS5016 2.1.0.0R3
- Lantronix EDS5032 2.1.0.0R3
Timeline
- 2026-03-10: advisory: CISA ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE-2025-67036 published
- 2026-03-11: patched: Firmware version 2.2.0.0R1 released