An issue was discovered in Lantronix EDS5000 2.1.0.0R3....
Critical severity
Unreviewed
Published
Mar 11, 2026
to the GitHub Advisory Database
•
Updated Sep 4, 2026
Description
Published by the National Vulnerability Database
Mar 11, 2026
Published to the GitHub Advisory Database
Mar 11, 2026
Last updated
Sep 4, 2026
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS injection vulnerabilities due to missing sanitization of input parameters. An attacker can inject arbitrary commands in delete actions of various objects, such as server keys, users, and known hosts. Commands are executed with root privileges.
References