An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
References
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
No history.
Information
Published : 2026-03-11 17:16
Updated : 2026-09-04 21:17
NVD link : CVE-2025-67037
Mitre link : CVE-2025-67037
CVE.ORG link : CVE-2025-67037
JSON object : View
Products Affected
lantronix
- eds5008
- eds5016
- eds5032
- eds5016_firmware
- eds5032_firmware
- eds5008_firmware
