CVE-2025-67037
CVSS Score
8.8
EPSS Score
0.3%
EPSS Percentile
24th
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
| CWE | CWE-78 |
| Vendor | n/a |
| Product | n/a |
| Published | Mar 11, 2026 |
| Last Updated | Jul 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new high vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Lantronix / EDS5000 series
0 โค 2.1.0.0R3
Lantronix / G520 series
0 < 2.6.0.4R6
Lantronix / X300 series
0 < 2.6.0.4R6
References
lantronix.com: https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 github.com: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
Credits
Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS5000 series to CISA. Lantronix reported the vulnerability for the G520 series and X300 series to CISA.