CVE-2025-67035 describes multiple critical OS injection vulnerabilities affecting Lantronix EDS5000 series devices (EDS5008, EDS5016, EDS5032) running firmware 2.1.0.0R3. These flaws allow unauthenticated, remote attackers to execute arbitrary commands with root privileges by injecting malicious input into SSH client and server delete actions due to missing input sanitization. Rated 9.8 CVSS (Critical), the vulnerability poses a significant risk due to its low attack complexity and potential for complete system compromise. While CISA has issued an alert, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.