peter bassill · operator
$ cve CVE-2025-67038 JSON

CVE-2025-67038 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 19.3% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2026-06-26.

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.26% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2026-06-26
Public exploitnone known
Published2026-03-11
Last modified2026-09-08

CISA KEV

NameLantronix EDS5000 Code Injection Vulnerability
Added2026-06-23
Due2026-06-26
Vendor / productLantronix / EDS5000
Ransomware usenone reported

Affected (40)

VendorProduct
lantronixeds5008
lantronixeds5008 firmware
lantronixeds5016
lantronixeds5016 firmware
lantronixeds5032
lantronixeds5032 firmware
lantronixg526gp12s
lantronixg526gp12s firmware
lantronixg526gp17s
lantronixg526gp17s firmware
lantronixg526gp1as
lantronixg526gp1as firmware
lantronixg526gp1asg
lantronixg526gp1asg firmware
lantronixg526gp1cs
lantronixg526gp1cs firmware
lantronixg527gp22s
lantronixg527gp22s firmware
lantronixg527gp27s
lantronixg527gp27s firmware
lantronixg527gp2as
lantronixg527gp2as firmware
lantronixg527gp2asg
lantronixg527gp2asg firmware
lantronixg528gp2fs
lantronixg528gp2fs firmware
lantronixg528gp2fsg
lantronixg528gp2fsg firmware
lantronixg528gp2fsgc
lantronixg528gp2fsgc firmware
lantronixx300f202s
lantronixx300f202s firmware
lantronixx303f202s
lantronixx303f202s firmware
lantronixx304g000s
lantronixx304g000s firmware
lantronixx304g002s
lantronixx304g002s firmware
lantronixx304g00as
lantronixx304g00as firmware

References

→ the Explorer  ·  watch your stack  ·  NVD