Database/Control plane, storage & DevOps

Lantronix EDS5000 serial-to-Ethernet device server: Root command execution on the device server
Impact
Root command execution on the device server. The HTTP RPC module writes a log line whenever a login fails, and it builds that log line by shell-concatenating the attempted username — so a failed login with a malicious username is enough to run arbitrary commands as root. This CVE is in CISA's Known Exploited Vulnerabilities catalog, meaning it has been used in real attacks.
Who can reach it
No valid credentials needed — the trigger is a failed authentication attempt, so the attacker just needs network reachability to the device's HTTP interface and controls the username field.
What to do
Firmware flash is required; there's no config toggle to disable the vulnerable logging path. Given the confirmed exploitation, treat this as urgent — patch every EDS5000 in the fleet ahead of routine maintenance windows, one device at a time (each flash drops the serial sessions it's bridging).
References
Related entries
- Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCVE-2025-6802 · Marvell QConvergeConsole (QLogic Fibre Channel / FC-NVMe / CNA HBA management web console), 5.5.0.78 and earlierCritical
- Citrix NetScaler: Memory overflowCVE-2025-7775 · Citrix NetScalerCritical
- Palo Alto PAN-OS: Buffer overflow in the User-ID Captive PortalCVE-2026-0300 · Palo Alto PAN-OSCritical
- Ivanti Endpoint Manager Mobile: Code injectionCVE-2026-1281 · Ivanti Endpoint Manager MobileCritical
- Ivanti Endpoint Manager Mobile: Code injectionCVE-2026-1340 · Ivanti Endpoint Manager MobileCritical
- OSNEXUS QuantaStor: unauthenticated Kapacitor access gives remote code execution as root on the storage nodeCVE-2026-18265 · OSNEXUS QuantaStor (unauthenticated Kapacitor service)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.