Lantronix EDS5000 Vulnerability
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
CVSS Score
9.8
CRITICAL
Published
23 Jun 2026 00:00
Modified
N/A
Vendor
Lantronix
Product
EDS5000
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-78
CWE-94
Affected Systems
Lantronix
EDS5000
Lantronix
EDS5000
External Links
KEV Status
Known Exploited Vulnerability