Lantronix EDS3000PS and EDS5000 TFTP Command Injection Vulnerability Allowing Root Privilege Code Execution

Vulnerability

A command injection vulnerability has been identified in the Lantronix EDS3000PS version 3.1.0.0R2 TFTP client. The vulnerability arises because the host parameter is not properly sanitized on the Filesystem Browser page. This flaw can be exploited to escape the original command context and execute arbitrary commands with root privileges.

Impact

Exploitation of this vulnerability allows for authentication bypass and execution of arbitrary commands with root privileges.

Added: Mar 11, 2026, 5:32 PM
Updated: Mar 11, 2026, 5:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.5
remediation
0.0
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.