Back to CVE List

CVE-2025-67041

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browser page is not properly sanitized. This can be exploited to escape from the original command and execute an arbitrary one with root privileges.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-78
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!