CVE-2025-67038
Publiée le 2026-03-11 · Dernière modification le 2026-09-04 KEV — activement exploitée
Les appareils Lantronix EDS5000 utilisant la version 2.1.0.0R3 sont affectés par une faille d'injection de commande dans le processus de connexion. Un attaquant non authentifié ayant un accès réseau à l'appareil peut obtenir un contrôle root complet en envoyant un nom d'utilisateur spécialement conçu lors d'une tentative de connexion échouée. Cela ne nécessite aucune interaction de l'utilisateur et est facile à exécuter à distance.
ACTIVEMENT EXPLOITÉE (KEV DE LA CISA)
Lantronix EDS5000 Code Injection Vulnerability — Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. Ajoutée au catalogue KEV de la CISA le 2026-06-23. Date limite de correction (agences fédérales américaines) : 2026-06-26.
DÉTAIL DU VECTEUR CVSS
RÉFÉRENCES
Description officielle du NVD (en anglais)
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.