CVE-2025-67034

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

Credits

Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS5000 series to CISA.
Lantronix reported the vulnerability for the G520 series and X300 series to CISA.

References