CVE-2025-67036
8.8Lantronix · EDS5000
A command injection vulnerability in the Lantronix EDS5000 Log Info page allows an authenticated attacker to execute arbitrary OS commands with root privileges via the file name parameter.
Executive summary
A critical command injection vulnerability in Lantronix EDS5000 devices allows an authenticated attacker to achieve full root-level compromise of the affected hardware.
Vulnerability
The Log Info page fails to sanitize the file name parameter, which enables an authenticated attacker to inject and execute arbitrary operating system commands with root privileges.
Business impact
The ability to execute commands with root privileges poses a severe risk to organizational security, as it grants an attacker complete control over the affected device. This could lead to unauthorized network access, data interception, or the permanent disruption of critical industrial operations, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Consult the official CISA ICS advisory (ICSA-26-069-02) for available firmware updates and apply them to all affected EDS5000 units immediately.
Proactive Monitoring: Monitor device logs and network traffic for unusual command execution patterns or unauthorized attempts to access system files through the web interface.
Compensating Controls: Restrict access to the management interface of the EDS5000 to trusted administrative IP addresses only, and employ a Web Application Firewall (WAF) to detect and block malicious shell command injections.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for root-level command execution, this vulnerability represents a significant threat to device integrity. Administrators must prioritize updating affected firmware as soon as the vendor provides a patch and strictly enforce network-level access controls to limit the exposure of the management interface to unauthorized users.