An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
Credits
Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS5000 series to CISA.
Lantronix reported the vulnerability for the G520 series and X300 series to CISA.