Lantronix EDS3000PS and EDS5000
Multiple critical vulnerabilities were discovered in Lantronix EDS3000PS and EDS5000 devices, affecting versions 3.1.0.0R2 and 2.1.0.0R3 respectively. These flaws include OS command injection, authentication bypass, and unverified password change capabilities that could allow attackers to execute code with root privileges and bypass authentication. Lantronix has released firmware patches (EDS3000PS 3.2.0.0R2 and EDS5000 2.2.0.0R1) and CISA recommends immediate mitigation including network isolation and access restrictions.
Summary
Multiple critical vulnerabilities were discovered in Lantronix EDS3000PS and EDS5000 devices, affecting versions 3.1.0.0R2 and 2.1.0.0R3 respectively. These flaws include OS command injection, authentication bypass, and unverified password change capabilities that could allow attackers to execute code with root privileges and bypass authentication. Lantronix has released firmware patches (EDS3000PS 3.2.0.0R2 and EDS5000 2.2.0.0R1) and CISA recommends immediate mitigation including network isolation and access restrictions.
Indicators of Compromise
- cve — CVE-2025-67034
- cve — CVE-2025-67035
- cve — CVE-2025-67036
- cve — CVE-2025-67037
- cve — CVE-2025-67038
- cve — CVE-2025-67039
- cve — CVE-2025-70082
- cve — CVE-2025-67041