eds5016_firmware vulnerabilities
CVEs whose affected-version data names the eds5016_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-67037High· 8.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection. Injected commands are executed with root privileges.
▾ Twilightlantronix · eds5032_firmwareEPSS 0.39%via NVD
CVE-2025-67038Critical· 9.8CISA KEVPoCAn issue was discovered in Lantronix EDS5000 2.1.0.0R3
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…
▾ Hadallantronix · eds5008_firmwareEPSS 19%via NVD