PT-2025-52605 · Lantronix · Eds3000Ps Series+2

CVE-2025-67041

·

Published

2025-12-19

·

Updated

2026-03-15

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lantronix EDS3000PS version 3.1.0.0R2
Description The host parameter of the TFTP client within the Filesystem Browser page does not undergo proper sanitization. This allows for command escape and the execution of arbitrary commands with root privileges. The vulnerable component is the TFTP client.
Recommendations Apply input validation and sanitization to the host parameter of the TFTP client in the Filesystem Browser page.

Fix

Authentication Bypass Using an Alternate Path or Channel

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67041

Affected Products

Eds3000Ps Series
Eds3008Ps1Ns Firmware
Eds3016Ps1Ns Firmware