CVE-2025-67034
8.8Lantronix · EDS5000
A command injection vulnerability in the Lantronix EDS5000 allows authenticated attackers to execute arbitrary OS commands with root privileges via the SSL credential management interface.
Executive summary
A critical command injection vulnerability in the Lantronix EDS5000 allows authenticated attackers to achieve full system compromise with root privileges.
Vulnerability
This vulnerability is an OS command injection flaw located within the name parameter of the SSL credential deletion function. An authenticated attacker with low-level access to the management interface can leverage this input to execute arbitrary commands as the root user.
Business impact
The ability to execute commands with root privileges represents a total compromise of the affected device. Successful exploitation could lead to full loss of confidentiality, integrity, and availability of the device, potentially allowing an attacker to pivot into the internal network or disrupt critical operations. Given the CVSS score of 8.8, this vulnerability poses a high risk to organizational security posture.
Remediation
Immediate Action: Consult the official CISA ICS advisory (ICSA-26-069-02) and contact Lantronix support to obtain the necessary firmware update to remediate this command injection flaw.
Proactive Monitoring: Review system and management logs for suspicious activity involving the SSL credential management interface, specifically looking for unusual character strings in parameter inputs.
Compensating Controls: Restrict access to the management interface to authorized personnel only and ensure the device is segmented from public-facing networks to limit the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing the Lantronix EDS5000 should prioritize identifying instances of version 2.1.0.0R3 within their infrastructure. Due to the potential for full system control, it is essential to implement strict access controls on the management interface while awaiting specific patch instructions from the vendor.