[0day-rubbish] Lantronix SGX5150 9.13.0.0R7 Authenticated FsBrowseClean command injection to root RCE (7.2)
Lantronix SGX5150 firmware has an authenticated command-injection flaw that can yield root code execution.
The 0day Rubbish Research Team disclosed an authenticated OS command injection (CWE-78) in Lantronix SGX5150 firmware 9.13.0.0R7, an IT/OT device server. The FsBrowseClean handler insufficiently filters a path parameter, allowing injected commands and root code execution. The issue is scored 7.2. No CVE or in-the-wild exploitation is mentioned.
42