
CVE-2025-67037 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. An authenticated attacker can inject OS commands into the "tunnel" parameter when killing a tunnel connection.… https://www.cve.org/CVERecord?id=CVE-2025-67037
Post summary
The post announces that an authenticated attacker can perform command injection via the "tunnel" parameter on the Lantronix EDS5000, providing technical details but no PoC, patch information, or evidence of active exploitation.
