---
id: CVE-2025-67034
title: An issue was discovered in Lantronix EDS5000 2.1.0.0R3
summary: >-
  An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated
  attacker can inject OS commands into the "name" parameter when deleting SSL
  credentials through the management interface. Injected commands are executed
  with root p…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-03-11'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67034'
references:
  - url: 'http://eds5000.com'
    label: cve@mitre.org
  - url: 'http://lantronix.com'
    label: cve@mitre.org
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00496
epssPercentile: 0.40103
ingestedAt: '2026-06-29T13:24:34.800Z'
---

## Overview

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
