Lantronix EDS5000 OS Command Injection Vulnerability Allowing Root Privilege Execution

Vulnerability

A command injection vulnerability has been identified in the Lantronix EDS5000 version 2.1.0.0R3. The issue arises on the Log Info page, where users can access log files by entering their names. Due to inadequate sanitization of the file name parameter, an authenticated attacker can inject arbitrary operating system commands that are executed with root privileges.

Impact

Exploitation of this vulnerability allows for authentication bypass and execution of injected commands with root privileges.

Added: Mar 11, 2026, 5:34 PM
Updated: Mar 11, 2026, 5:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.