Junglewise Threat Intelligence

CVE-2025-67037: Lantronix EDS5000 OS command injection in tunnel parameter

CVE-2025-67037 · Severity: high · CVSS 8.8 · Published 2026-03-11

Technologies: Lantronix Eds5016, Lantronix Eds5008 Firmware, Lantronix Eds5016 Firmware, Lantronix Eds5032 Firmware, Lantronix Eds5008, Lantronix Eds5032. Vendors: Lantronix.

Executive brief

Lantronix EDS5000 is a device server used to connect industrial equipment to networks. A security flaw allows a logged-in user to execute unauthorized commands with full administrative (root) privileges by manipulating the process of closing a tunnel connection. This could lead to a complete takeover of the device, potentially disrupting industrial operations or providing a foothold for further network attacks.

Technical details

An OS command injection vulnerability exists in Lantronix EDS5000 firmware version 2.1.0.0R3. The flaw is located in the handling of the 'tunnel' parameter when an authenticated user attempts to terminate a tunnel connection. Due to insufficient input sanitization, an attacker can inject shell commands that are executed with root privileges. While the CISA-ADP CVSS score is 8.8 (Low Privileges), some vendor documentation suggests a score of 7.2 (High Privileges); however, the vulnerability consistently results in full system compromise. Lantronix has released firmware version 2.2.0.0R1 to address this issue.

Affected products

  • Lantronix EDS5000 series (EDS5008, EDS5016, EDS5032) 2.1.0.0R3

Timeline

  • 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
  • 2026-03-11: disclosed: CVE published to NVD
  • 2026-03-11: patched: Lantronix released firmware 2.2.0.0R1 to address the issue

References

Related threats