Lantronix EDS5000 OS Command Injection Vulnerability Allowing Root Privilege Execution

Vulnerability

A command injection vulnerability has been identified in the Lantronix EDS5000 model running firmware version 2.1.0.0R3. The issue arises in the HTTP RPC module, where failed authentication logs are generated by executing a shell command. The vulnerability allows attackers to inject arbitrary operating system commands through the username parameter, which is executed with root privileges.

Impact

Exploitation of this vulnerability allows for authentication bypass and execution of injected commands with root privileges.

Added: Mar 11, 2026, 5:35 PM
Updated: Mar 11, 2026, 5:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.