Lantronix EDS5000 OS Command Injection Vulnerability Allowing Root Privilege Execution
Vulnerability
A command injection vulnerability has been identified in the Lantronix EDS5000 model running firmware version 2.1.0.0R3. The issue arises in the HTTP RPC module, where failed authentication logs are generated by executing a shell command. The vulnerability allows attackers to inject arbitrary operating system commands through the username parameter, which is executed with root privileges.
Impact
Exploitation of this vulnerability allows for authentication bypass and execution of injected commands with root privileges.
Added: Mar 11, 2026, 5:35 PM
Updated: Mar 11, 2026, 5:35 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
7.4remediation
0.0relevance
3.8threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
