Executive brief
A vulnerability exists in Lantronix EDS3000PS device servers, which are used to connect serial equipment to networks. An attacker can exploit a flaw in the device's file management interface to take complete control of the system with the highest level of access (root). This could lead to unauthorized data access, disruption of connected industrial equipment, or use of the device as a foothold for further network attacks.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Lantronix EDS3000PS firmware version 3.1.0.0R2. The vulnerability is located in the 'host' parameter of the TFTP client within the Filesystem Browser page, which fails to properly sanitize user input. While command injection typically requires authentication, this vulnerability is often discussed in the context of associated authentication bypass flaws (CWE-288) in the same product, leading to a CVSS score of 9.8. An attacker can use shell metacharacters to escape the intended TFTP command and execute arbitrary system commands as the root user. Lantronix recommends upgrading to EDS3000PS version 3.2.0.0R2 to resolve this issue.
Affected products
- Lantronix EDS3000PS firmware 3.1.0.0R2
- Lantronix EDS3008PS1NS firmware 3.1.0.0R2
- Lantronix EDS3016PS1NS firmware 3.1.0.0R2
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE published to NVD
- 2026-03-11: patched: Lantronix released EDS3000PS version 3.2.0.0R2