---
id: CVE-2025-67035
title: An issue was discovered in Lantronix EDS5000 2.1.0.0R3
summary: >-
  An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH
  Server pages are affected by multiple OS injection vulnerabilities due to
  missing sanitization of input parameters. An attacker can inject arbitrary
  commands …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-03-11'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67035'
references:
  - url: 'http://eds5000.com'
    label: cve@mitre.org
  - url: 'http://lantronix.com'
    label: cve@mitre.org
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00414
epssPercentile: 0.3298
ingestedAt: '2026-06-29T13:24:34.802Z'
---

## Overview

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
