Executive brief
Lantronix EDS5000 is a device server used to connect industrial equipment to networks. A security flaw allows a logged-in user to execute unauthorized commands with full administrative (root) privileges by manipulating the process of closing a tunnel connection. This could lead to a complete takeover of the device, potentially disrupting industrial operations or providing a foothold for further network attacks.
Technical details
An OS command injection vulnerability exists in Lantronix EDS5000 firmware version 2.1.0.0R3. The flaw is located in the handling of the 'tunnel' parameter when an authenticated user attempts to terminate a tunnel connection. Due to insufficient input sanitization, an attacker can inject shell commands that are executed with root privileges. While the CISA-ADP CVSS score is 8.8 (Low Privileges), some vendor documentation suggests a score of 7.2 (High Privileges); however, the vulnerability consistently results in full system compromise. Lantronix has released firmware version 2.2.0.0R1 to address this issue.
Affected products
- Lantronix EDS5000 series (EDS5008, EDS5016, EDS5032) 2.1.0.0R3
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE published to NVD
- 2026-03-11: patched: Lantronix released firmware 2.2.0.0R1 to address the issue