CVE-2025-67034 is an authenticated OS command injection vulnerability affecting Lantronix EDS5000 series devices running firmware version 2.1.0.0R3. An authenticated attacker can exploit this flaw remotely with low complexity by injecting commands into the "name" parameter during SSL credential deletion, leading to root-level execution and full system compromise. This vulnerability carries a CVSS score of 8.8 (HIGH) due to its network attack vector, low privileges required, and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.