CVE-2025-67038

Published Mar 11, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-67038 is an OS command injection vulnerability affecting Lantronix EDS5000 devices, specifically version 2.1.0.0R3. This flaw resides within the HTTP RPC module, which logs failed user authentication attempts by executing shell commands. The vulnerability arises because the username parameter is directly incorporated into these shell commands without proper sanitization, allowing an attacker to inject arbitrary operating system commands. Exploitation of CVE-2025-67038 does not require prior authentication and can be performed remotely over the network by leveraging intentionally failed login attempts. The injected commands execute with root privileges, enabling complete system compromise. Given that Lantronix EDS5000 devices are frequently deployed in industrial control system (ICS) environments for serial-to-Ethernet connectivity, a successful exploit could provide attackers with a foothold into operational technology (OT) networks. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation.

Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Source
cve@mitre.org
NVD status
Analyzed
Products
eds5032_firmware, eds5008_firmware, eds5016_firmware

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Lantronix EDS5000 Code Injection Vulnerability
Exploit added on
Jun 23, 2026
Exploit action due
Jun 26, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-94

Social media

Hype score
Not currently trending
  1. Root shell via the username field. No credentials needed. CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters. Exploited in the wild before Forescout published the technical details. CISA KEV since June 23.

    @Shift6Security

    21 Jul 2026

    85 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Update: CISA has formally added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog, elevating the threat's official standing and reinforcing mandatory remediation timelines for federal agencies. https://t.co/vBACtYVbrR

    @f1tym1

    5 Jul 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Lantronix EDS5000 flaw (CVE-2025-67038, CVSS 9.8): attackers reverse-engineered the patch and exploited it before public disclosure. Unauth command injection → root, on OT serial-to-IP bridges nobody inventories. Now on CISA KEV. Read here: https://t.co/Y2TQY1DWVj https://t.c

    @DarkInvaderIO

    2 Jul 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISA added three Ubiquiti UniFi OS flaws and Lantronix EDS5000 CVE-2025-67038 to KEV. Patch or isolate management paths and inspect for unauthorized changes. https://t.co/zIry48QRZd

    @InfosecDotWatch

    1 Jul 2026

    53 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Patch-and-pray doesn't work in OT. Attackers reverse-engineered a Lantronix fix and exploited CVE-2025-67038 before the research even went public. Your patch is their roadmap. https://t.co/iC8dMB8DwF

    @geeknik

    30 Jun 2026

    233 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-67038 | Lantronix EDS5000 (serial-to-IP bridge, firmware ≤2.1.0.0R3) Attackers inject OS commands via the username field in the HTTP RPC auth log — no creds needed. CVSS 9.8 | In KEV: Jun 23, 2026

    @polsia

    29 Jun 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Recent zero-day exploits like CVE-2026-20245 (Cisco SD-WAN) & CVE-2025-67038 (Lantronix EDS5000) show active network device targeting. These vulnerabilities threaten data privacy & integrity in transit via interception & command execution. #Cybersecurity #NetworkSecur

    @YourAnon_irc

    29 Jun 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-67038はLantronix EDS5000のコードインジェクション脆弱性。攻撃者がユーザー名パラメータにOSコマンドを注入し、root権限で実行される危険性がある。

    @Joe_Biden_ja

    29 Jun 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 1. CVE-2025-67038 added to CISA KEV catalog: Lantronix EDS5000 vulnerable to code injection allowing root-level OS command execution via username parameter. 2. No confirmed ransomware use yet; urgent mitigation required by June 26 following CISA BOD 26-04 guidelines. 3. Watch for

    @ThreatPing

    28 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Recent findings reveal encrypted DNS (TLS/QUIC) still exposes critical metadata, impacting data privacy in transit. Also, active exploits target Cisco SD-WAN zero-day (CVE-2026-20245) & Lantronix EDS5000 (CVE-2025-67038). Stay vigilant! #Cybersecurity #InfoSec #ZeroDay

    @YourAnon_irc

    28 Jun 2026

    85 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2025-67038: Lantronix EDS5000にてOSコマンドインジェクションの脆弱性が報告。CVSSスコア未公開。攻撃者がルート権限で命令を実行可能。パッチ適用が急務です。

    @Joe_Biden_ja

    28 Jun 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 現在、CVE-2025-67038に注目。Lantronix EDS5000のコードインジェクション脆弱性で、ルート権限のもとに任意のOSコマンドが実行される事例あり。注意が必要。

    @Joe_Biden_ja

    27 Jun 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Most people will see the headline. The real signal is what lantronix-eds5000-cve-2025-67038… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/6z47aE7VPr

    @lucasverdan

    26 Jun 2026

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. lantronix-eds5000-cve-2025-67038-active-exploitation is not just a headline. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/lLwwd1KsRm

    @fynn_JourX

    26 Jun 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-67038 se explotó como zero-day desde el 5 de abril, semanas antes del patch. Forescout cree que alguien hizo reversing del parche del 20 de febrero. https://t.co/qccr8V6HSh

    @NeoteoCom

    26 Jun 2026

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. lantronix-eds5000-cve-2025-67038-active-exploitation is not just a headline. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/ctMUcuMFZT

    @SocXAInvaders

    26 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🛑 Lantronix EDS5000 exploitation shows why edge device patch windows are… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Details → https://t.co/6z47aE7VPr

    @lucasverdan

    26 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Legacy exposure keeps paying off for attackers. Lantronix EDS5000 exploitation shows why edge device patc… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Read → https://t.co/lLwwd1KsRm

    @fynn_JourX

    26 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. For defenders, lantronix eds5000 exploitation shows why edge device patch wind… should move fast. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Details → https://t.co/ctMUcuMFZT

    @SocXAInvaders

    26 Jun 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CISA's deadline for the Lantronix EDS5000 vulnerability is today. CVE-2025-67038. CVSS 9.8. Actively exploited. The bug itself is almost embarrassingly simple: a username field gets concatenated directly into a shell command with no sanitization. Type the wrong username, run

    @ByteDrop453

    26 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CISA warnt: Kritische Lantronix EDS5000-Lücke CVE-2025-67038 wird aktiv ausgenutzt CISA warnt vor CVE-2025-67038 (CVSS 9.8) in Lantronix EDS5000 Series. Die Lücke https://t.co/Q1sY34KmS4 https://t.co/h6w1zmNsQ8

    @schoenfelderED

    26 Jun 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. ⚠️ UPDATE - Forescout says CVE-2025-67038 was exploited as a zero-day. The Lantronix flaw was used against honeypots as early as April 5, weeks before BRIDGE:BREAK was publicly disclosed. Attackers may have reverse-engineered the Feb. 20 patch to build the exploit. Read: h

    @TheHackersNews

    26 Jun 2026

    37623 Impressions

    16 Retweets

    62 Likes

    9 Bookmarks

    4 Replies

    3 Quotes

  23. A critical Lantronix flaw is now under active exploitation. CISA says CVE-2025-67038 affects EDS5000 Series devices and can let attackers run commands with root privileges. Federal civilian agencies have until June 26, 2026, to patch. https://t.co/10IVvh7ajQ

    @ridwanseun12

    26 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVE-2025-67038に関する情報。Lantronix EDS5000では、コードインジェクションにより、攻撃者がroot権限で任意のOSコマンドを実行できる。XSSの恐れもあり。

    @Joe_Biden_ja

    26 Jun 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. CISA added CVE-2025-67038 in Lantronix EDS5000 devices to its KEV list on June 23, 2026, confirming active exploitation of an unauthenticated OS command injection vulnerability, NHS England reported. https://t.co/zEwHkMUMFt

    @threatcluster

    25 Jun 2026

    78 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🚨 Lantronix EDS5000 Command Injection (CVE-2025-67038) Exploited in the Wild, Now in CISA KEV #cybersecurity #infosec #threatintel https://t.co/AoXJP1xPJg

    @zerodaywire

    25 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. Lantronix serial-to-IP converters are getting hit in the wild now. CVE-2025-67038 from the April BRIDGE:BREAK disclosure. If you're running OT gear with these boxes, patch or segment. https://t.co/sgRWuG6rNU

    @elsontech

    25 Jun 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. ⚠️ CVE-2025-67038: Lantronix EDS5000 serial device server — code injection via unauthenticated web interface, now on CISA KEV. ICS/OT environments using these serial-to-IP gateways should patch or isolate immediately. https://t.co/1NcAogqaaO

    @colibrisec

    25 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  29. แจ้งเตือนช่องโหว่ Critical ใน Lantronix EDS5000 ถูกนำไปใช้โจมตี ขอให้ผู้ดูแลระบบเร่งอัปเดต Firmware ศูนย์ประสานการรักษา

    @ThaiCERTByNCSA

    25 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. แจ้งเตือนช่องโหว่ Critical ใน Lantronix EDS5000 ถูกนำไปใช้โจมตี ขอให้ผู้ดูแลระบบเร่งอัปเดต Firmware ศูนย์ประสานการรักษา

    @ThaiCERTByNCSA

    25 Jun 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. حذرت وكالة الأمن السيبراني الأمريكية من استغلال نشط للثغرة CVE-2025-67038 في أجهزة لانترونيكس EDS5000، ودعت إلى تطبيق التحديثات الأمنية بشكل عاجل. 📌 للتفاصيل الك

    @ncnarabic

    25 Jun 2026

    65 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. CISA alerts on CVE-2025-67038—a critical code injection flaw exploited in Lantronix EDS5000 devices. Federal agencies must patch by June 26, 2026. Assess your inventory and update now! #Lantronix #CISA #PatchNow #Cybersecurity #RemoteCodeExecution https://t.co/k63Pj63i6V

    @SOCMinute

    25 Jun 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  33. Attackers are injecting OS commands through authentication parameters in Lantronix EDS5000 devices to gain root access (CVE-2025-67038). TRC analysis shows compromised devices serve as footholds for lateral movement across connected networks. Runtime segmentation helps contain

    @aviatrixtrc

    24 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. CISA warns of active exploitation of CVE-2025-67038, a critical flaw in Lantronix EDS5000 devices. https://t.co/Y0mLtrDt8S

    @f1tym1

    24 Jun 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. 🚨 CISA warns CVE-2025-67038 (CVSS 9.8) in Lantronix EDS5000 is being actively exploited a code injection flaw letting attackers run root-privileged commands via unsanitized username input. FCEB agencies must patch by June 26, 2026.

    @techepages

    24 Jun 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  36. A command injection flaw in Lantronix EDS5000 serial-to-Ethernet device servers hit CISA's KEV catalog yesterday. CVE-2025-67038, CVSS 9.8. Federal civilian agencies have until June 26 to patch. That's 48 hours. The mechanics are as clean as they get. The HTTP RPC module

    @GoCocoaAI

    24 Jun 2026

    95 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  37. A critical Lantronix flaw is now under active exploitation. CISA says CVE-2025-67038 affects EDS5000 Series devices and can let attackers run commands with root privileges. Federal civilian agencies have until June 26, 2026, to patch. Learn more: https://t.co/oAxbINfejl https:

    @TheHackersNews

    24 Jun 2026

    23845 Impressions

    25 Retweets

    67 Likes

    7 Bookmarks

    3 Replies

    4 Quotes

  38. 🚨 CISA KEV Catalog Update June 2026 (status on 24.06.2026) - actively exploited vulnerabilities in the database: 🔹 Ubiquiti UniFi OS: CVE-2026-34908/34909/34910 (due 6/26) 🔹 Lantronix EDS5000: CVE-2025-67038 (due 6/26) 🔹 Splunk Enterprise: CVE-2026-20253 (due 6/21)

    @techepages

    24 Jun 2026

    104 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Today’s CTI call: patch/exposure beats actor-label hunting. CISA added 4 actively exploited device/control-plane bugs to KEV: - Ubiquiti UniFi OS: CVE-2026-34908 / 34909 / 34910 - Lantronix EDS5000: CVE-2025-67038 Treat this as immediate asset inventory + management-plane

    @alphahunt_io

    24 Jun 2026

    112 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  40. 米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/23追加) 🛡CVE-2025-67038 ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/

    @piyokango

    24 Jun 2026

    5530 Impressions

    1 Retweet

    6 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  41. 🚨 CVE-2025-67038: Lantronix EDS5000 HTTP RPC module Command Execution Critical Vulnerability Alert! Lantronix is affected by CVE-2025-67038. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/8CrY7rh8ah 🔍 Identify Targets via ZoomEye: Filter: https:

    @zoomeye_team

    24 Jun 2026

    2017 Impressions

    8 Retweets

    18 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  42. CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Jun 23) CVE-2025-67038 Lantronix EDS5000のコードインジェクション脆弱性 CVE-2026-34908 Ubiquiti UniFi OSの不適切なアクセ

    @foxbook

    24 Jun 2026

    290 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. 🚨 WARNING: Lantronix EDS5000 suffers critical code injection flaw CVE-2025-67038 allowing root-level OS command execution via username parameter. ⚡️ CISA added it to Known Exploited Vulnerabilities catalog with patch deadline June 26. Immediate mitigation required.

    @ThreatPing

    23 Jun 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、Lantronix EDS5000のCVE-2025-67038とUbiquiti UniFi OSのCVE-2026-34908~34910の4件を追加。対処期限はいずれも3日後の6/26。ランサム

    @__kokumoto

    23 Jun 2026

    1045 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  45. 🚨 CRITICAL: CVE-2025-67038 - Lantronix EDS5000 code injection flaw allows attackers to execute arbitrary OS commands as root via username parameter. CISA KEV listed. Patch immediately. #CVE #PatchNow https://t.co/focVviYfVg

    @DFIR_Lab

    23 Jun 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 🚨 4 new CISA KEV adds today CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2025-67038 https://t.co/0StDFCzdCI #boarnet #cybersecurity #cisakev #cve #threatintelligence #malware

    @boarnetio

    23 Jun 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  47. CVE-2025-67038 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is d… https://t.co/40mJZpH0IG

    @CVEnew

    15 Mar 2026

    194 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations