CVE-2025-67035

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
References
Link Resource
http://eds5000.com Not Applicable
http://lantronix.com Product
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*

History

19 Mar 2026, 20:17

Type Values Removed Values Added
CPE cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*
cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0:r3:*:*:*:*:*:*
cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*
First Time Lantronix eds5016 Firmware
Lantronix eds5008 Firmware
Lantronix eds5032 Firmware
Lantronix eds5016
Lantronix eds5008
Lantronix eds5032
Lantronix
References () http://eds5000.com - () http://eds5000.com - Not Applicable
References () http://lantronix.com - () http://lantronix.com - Product
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 - Third Party Advisory, US Government Resource
Summary
  • (es) Se descubrió un problema en Lantronix EDS5000 2.1.0.0R3. Las páginas del Cliente SSH y del Servidor SSH están afectadas por múltiples vulnerabilidades de inyección de sistema operativo debido a la falta de saneamiento de los parámetros de entrada. Un atacante puede inyectar comandos arbitrarios en acciones de eliminación de varios objetos, como claves de servidor, usuarios y hosts conocidos. Los comandos se ejecutan con privilegios de root.

12 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-94

11 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 17:16

Updated : 2026-03-19 20:17


NVD link : CVE-2025-67035

Mitre link : CVE-2025-67035

CVE.ORG link : CVE-2025-67035


JSON object : View

Products Affected

lantronix

  • eds5016_firmware
  • eds5016
  • eds5032
  • eds5008
  • eds5032_firmware
  • eds5008_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')