An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
Credits
Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS5000 series to CISA.
Lantronix reported the vulnerability for the G520 series and X300 series to CISA.