CVE-2025-67038 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 19.3% (pctl 97)
Patch first
On CISA KEV — known exploited in the wild, due 2026-06-26.
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 19.26% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | yes — remediate by 2026-06-26 |
| Public exploit | none known |
| Published | 2026-03-11 |
| Last modified | 2026-09-08 |
CISA KEV
| Name | Lantronix EDS5000 Code Injection Vulnerability |
|---|---|
| Added | 2026-06-23 |
| Due | 2026-06-26 |
| Vendor / product | Lantronix / EDS5000 |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| lantronix | eds5008 |
| lantronix | eds5008 firmware |
| lantronix | eds5016 |
| lantronix | eds5016 firmware |
| lantronix | eds5032 |
| lantronix | eds5032 firmware |
| lantronix | g526gp12s |
| lantronix | g526gp12s firmware |
| lantronix | g526gp17s |
| lantronix | g526gp17s firmware |
| lantronix | g526gp1as |
| lantronix | g526gp1as firmware |
| lantronix | g526gp1asg |
| lantronix | g526gp1asg firmware |
| lantronix | g526gp1cs |
| lantronix | g526gp1cs firmware |
| lantronix | g527gp22s |
| lantronix | g527gp22s firmware |
| lantronix | g527gp27s |
| lantronix | g527gp27s firmware |
| lantronix | g527gp2as |
| lantronix | g527gp2as firmware |
| lantronix | g527gp2asg |
| lantronix | g527gp2asg firmware |
| lantronix | g528gp2fs |
| lantronix | g528gp2fs firmware |
| lantronix | g528gp2fsg |
| lantronix | g528gp2fsg firmware |
| lantronix | g528gp2fsgc |
| lantronix | g528gp2fsgc firmware |
| lantronix | x300f202s |
| lantronix | x300f202s firmware |
| lantronix | x303f202s |
| lantronix | x303f202s firmware |
| lantronix | x304g000s |
| lantronix | x304g000s firmware |
| lantronix | x304g002s |
| lantronix | x304g002s firmware |
| lantronix | x304g00as |
| lantronix | x304g00as firmware |
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
→ the Explorer · watch your stack · NVD