CVE-2025-67037: Lantronix EDS5008 Firmware
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
Affected products
- Lantronix EDS5008 Firmware: version 2.1.0.0 only
- Lantronix EDS5016 Firmware: version 2.1.0.0 only
- Lantronix EDS5032 Firmware: version 2.1.0.0 only
Published 2026-03-11. Last modified 2026-09-04.