High severity8.8NVD Advisory· Published Mar 11, 2026· Updated Jul 5, 2026
CVE-2025-67034
CVE-2025-67034
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:*
- cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:*
- cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.cisa.gov/news-events/ics-advisories/icsa-26-069-02nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.