IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Lantronix EDS3000PS and EDS5000 (Update A)

CRITICAL
CVSS 9.8
Date 2026-08-25T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code with root-level privileges.

// Vulnerabilities (8)

CVE ID CVSS Score Severity Description
CVE-2025-67037 7.2 high
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
CVE-2025-70082 2.7 low
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
CVE-2025-67038 9.8 critical
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
CVE-2025-67035 7.2 high
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
CVE-2025-67034 7.2 high
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.
CVE-2025-67039 9.8 critical
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.
CVE-2025-67036 7.2 high
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The Log Info page allows users to see log files by specifying their names. Due to a missing sanitization in the file name parameter, an authenticated attacker can inject arbitrary OS commands that are executed with root privileges.
CVE-2025-67041 7.2 high
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.

// Remediations (7)

Patch: E210 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: https://ltrxdev.at
E210 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914404865/Latest+firmware+ePack+for+the+E210+Series+E213+E214+E215+E218+Cellular+Routers. (CVE-2025-67038)
Patch: EDS3000PS series: Upgrade to version 3.2.0.0R2 or later. The patch can be found here: https://ltrxde
EDS3000PS series: Upgrade to version 3.2.0.0R2 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1349189633/Latest+Firmware+for+the+EDS3000PS+series. (CVE-2025-67039, CVE-2025-70082, CVE-2025-67041)
Patch: X300 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: https://ltrxdev.atl
X300 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2135261185/Latest+firmware+for+the+X300+Series+X300+X303+X304. (CVE-2025-67034, CVE-2025-67036, CVE-2025-67037, CVE-2025-67038)
Mitigation: For more information or technical assistance, contact Lantronix support ([email protected]).
For more information or technical assistance, contact Lantronix support ([email protected]).
Mitigation: Latronix has released the following updates addressing these vulnerabilities. For more information,
Latronix has released the following updates addressing these vulnerabilities. For more information, see the Latronix Vulnerability Library (https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw).
Patch: E220 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: https://ltrxdev.at
E220 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914437633/Latest+firmware+ePack+for+the+E220+Series+E224+E225+E228+Cellular+Routers. (CVE-2025-67038)
Mitigation: For more information or technical assistance, contact Lantronix support ([email protected]).
For more information or technical assistance, contact Lantronix support ([email protected]).

// References