An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
History

Wed, 11 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-03-11T16:10:47.394Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67036

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-11T17:16:51.790

Modified: 2026-03-11T17:16:51.790

Link: CVE-2025-67036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.