Lantronix EDS5000
- 2.1.0.0R3
A command injection vulnerability has been identified in the Lantronix EDS5000 version 2.1.0.0R3. The issue arises on the Log Info page, where users can access log files by entering their names. Due to inadequate sanitization of the file name parameter, an authenticated attacker can inject arbitrary operating system commands that are executed with root privileges.
Exploitation of this vulnerability allows for authentication bypass and execution of injected commands with root privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.