CVE-2025-67041CRITICAL 9.8EPSS p25.6%
CVE-2025-67041CVE-2025-67041
lantronix / eds3016ps1ns_firmware
Description
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.33% probability of exploitation · percentile 25.6% · 2026-08-03T12:00:16Z |
| Published | 2026-03-11 |
| Last modified | 2026-07-05 |
Underlying weaknesses· 3
References
3
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Authentication Bypass Using an Alternate Path or Channelcwe-288 | 0% | live |
| Weakness | Unverified Password Changecwe-620 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-78 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.