THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-67034 (HIGH 7.2) — An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

[NVD] CVE-2025-67034 (HIGH 7.2) — An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

lownvdPublished 2026-03-11

CVE-2025-67034 CVSS: 7.2 HIGH Published: 2026-03-11T17:16:50.393

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "name" parameter when deleting SSL credentials through the management interface. Injected commands are executed with root privileges.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-67034