---
id: CVE-2025-67041
title: An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2
summary: >-
  An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter
  of the TFTP client in the Filesystem Browser page is not properly sanitized.
  This can be exploited to escape from the original command and execute an
  arbitrary …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-288
  - CWE-620
published: '2026-03-11'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67041'
references:
  - url: 'http://eds3000ps.com'
    label: cve@mitre.org
  - url: 'http://lantronix.com'
    label: cve@mitre.org
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00417
epssPercentile: 0.35664
ingestedAt: '2026-06-29T13:24:34.807Z'
---

## Overview

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
