CVE-2025-67037: Lantronix EDS5008 Firmware

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.

Affected products

  • Lantronix EDS5008 Firmware: version 2.1.0.0 only
  • Lantronix EDS5016 Firmware: version 2.1.0.0 only
  • Lantronix EDS5032 Firmware: version 2.1.0.0 only

Published 2026-03-11. Last modified 2026-09-04.