Lantronix EDS5000 OS Command Injection Vulnerability Allowing Root Privilege Execution

Vulnerability

A vulnerability exists in the Lantronix EDS5000 version 2.1.0.0R3, allowing authenticated attackers to inject operating system commands through the 'name' parameter while deleting SSL credentials via the management interface. The injected commands are executed with root privileges.

Impact

Exploitation of this vulnerability allows for authentication bypass and execution of injected OS commands with root privileges.

Added: Mar 11, 2026, 5:36 PM
Updated: Mar 11, 2026, 5:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.