What is CVE-2025-67038?
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Timeline
- 2026-03-11Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-23Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-26CISA federal remediation deadline (BOD 22-01)
- 2026-07-06NVD record last updated
CISA Known Exploited Vulnerability
Lantronix EDS5000 Code Injection Vulnerability
Affected product
Lantronix EDS5000
NVD also lists CPE entries for: Lantronix Eds5032 Firmware, Lantronix Eds5032, Lantronix Eds5008 Firmware, Lantronix Eds5008, Lantronix Eds5016 Firmware
Remediation Steps
- Apply vendor patches immediately per Lantronix security advisory
- Isolate affected Lantronix EDS5000 devices from untrusted network segments
- Monitor for signs of unauthorized access or code execution
- Implement network access controls to restrict inbound traffic to EDS5000 management interfaces
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 2 of July 2026 (July 13 – 19)
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.