CVE-2025-67037

8.8

Lantronix · EDS5000

A command injection vulnerability in the Lantronix EDS5000 allows authenticated attackers to execute arbitrary OS commands with root privileges via the tunnel parameter.

Executive summary

A high-severity command injection vulnerability in Lantronix EDS5000 allows authenticated attackers to gain root-level code execution.

Vulnerability

This vulnerability is an OS command injection flaw located in the tunnel parameter of the EDS5000 management interface. An authenticated attacker can trigger this vulnerability when terminating a tunnel connection, resulting in command execution at the root privilege level.

Business impact

The ability for an authenticated attacker to execute commands as root poses a critical risk to the confidentiality, integrity, and availability of the device. Successful exploitation allows for complete system compromise, potentially enabling lateral movement within the network or the disruption of industrial control processes. With a CVSS score of 8.8, this vulnerability represents a significant security threat that requires immediate attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Consult the official CISA ICS advisory ICSA-26-069-02 for vendor-specific patch availability and apply all recommended firmware updates to version 2.1.0.0R3 or higher as soon as they are made available by Lantronix.

Proactive Monitoring: Review system access logs for anomalous activity, particularly focusing on administrative sessions or unusual parameter inputs related to tunnel connection management.

Compensating Controls: Restrict access to the management interface of the EDS5000 to trusted IP addresses only, and ensure that all administrative accounts are protected with strong, unique credentials to limit the risk of an attacker gaining the required authentication.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for full system takeover, organizations utilizing the Lantronix EDS5000 must prioritize this issue. Administrators should monitor the vendor advisory closely for the release of a corrective patch and deploy it immediately upon verification to eliminate the command injection vector.

More Lantronix CVEs

Sources