CVE-2025-67038
Published Mar 11, 2026
Last updated a month ago
AI description
CVE-2025-67038 is an OS command injection vulnerability affecting Lantronix EDS5000 devices, specifically version 2.1.0.0R3. This flaw resides within the HTTP RPC module, which logs failed user authentication attempts by executing shell commands. The vulnerability arises because the username parameter is directly incorporated into these shell commands without proper sanitization, allowing an attacker to inject arbitrary operating system commands. Exploitation of CVE-2025-67038 does not require prior authentication and can be performed remotely over the network by leveraging intentionally failed login attempts. The injected commands execute with root privileges, enabling complete system compromise. Given that Lantronix EDS5000 devices are frequently deployed in industrial control system (ICS) environments for serial-to-Ethernet connectivity, a successful exploit could provide attackers with a foothold into operational technology (OT) networks. This vulnerability has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation.
- Description
- An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- eds5032_firmware, eds5008_firmware, eds5016_firmware
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Lantronix EDS5000 Code Injection Vulnerability
- Exploit added on
- Jun 23, 2026
- Exploit action due
- Jun 26, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-94
- Hype score
- Not currently trending
Root shell via the username field. No credentials needed. CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters. Exploited in the wild before Forescout published the technical details. CISA KEV since June 23.
@Shift6Security
21 Jul 2026
85 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
Update: CISA has formally added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog, elevating the threat's official standing and reinforcing mandatory remediation timelines for federal agencies. https://t.co/vBACtYVbrR
@f1tym1
5 Jul 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Lantronix EDS5000 flaw (CVE-2025-67038, CVSS 9.8): attackers reverse-engineered the patch and exploited it before public disclosure. Unauth command injection → root, on OT serial-to-IP bridges nobody inventories. Now on CISA KEV. Read here: https://t.co/Y2TQY1DWVj https://t.c
@DarkInvaderIO
2 Jul 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added three Ubiquiti UniFi OS flaws and Lantronix EDS5000 CVE-2025-67038 to KEV. Patch or isolate management paths and inspect for unauthorized changes. https://t.co/zIry48QRZd
@InfosecDotWatch
1 Jul 2026
53 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
Patch-and-pray doesn't work in OT. Attackers reverse-engineered a Lantronix fix and exploited CVE-2025-67038 before the research even went public. Your patch is their roadmap. https://t.co/iC8dMB8DwF
@geeknik
30 Jun 2026
233 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038 | Lantronix EDS5000 (serial-to-IP bridge, firmware ≤2.1.0.0R3) Attackers inject OS commands via the username field in the HTTP RPC auth log — no creds needed. CVSS 9.8 | In KEV: Jun 23, 2026
@polsia
29 Jun 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Recent zero-day exploits like CVE-2026-20245 (Cisco SD-WAN) & CVE-2025-67038 (Lantronix EDS5000) show active network device targeting. These vulnerabilities threaten data privacy & integrity in transit via interception & command execution. #Cybersecurity #NetworkSecur
@YourAnon_irc
29 Jun 2026
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038はLantronix EDS5000のコードインジェクション脆弱性。攻撃者がユーザー名パラメータにOSコマンドを注入し、root権限で実行される危険性がある。
@Joe_Biden_ja
29 Jun 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1. CVE-2025-67038 added to CISA KEV catalog: Lantronix EDS5000 vulnerable to code injection allowing root-level OS command execution via username parameter. 2. No confirmed ransomware use yet; urgent mitigation required by June 26 following CISA BOD 26-04 guidelines. 3. Watch for
@ThreatPing
28 Jun 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Recent findings reveal encrypted DNS (TLS/QUIC) still exposes critical metadata, impacting data privacy in transit. Also, active exploits target Cisco SD-WAN zero-day (CVE-2026-20245) & Lantronix EDS5000 (CVE-2025-67038). Stay vigilant! #Cybersecurity #InfoSec #ZeroDay
@YourAnon_irc
28 Jun 2026
85 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038: Lantronix EDS5000にてOSコマンドインジェクションの脆弱性が報告。CVSSスコア未公開。攻撃者がルート権限で命令を実行可能。パッチ適用が急務です。
@Joe_Biden_ja
28 Jun 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
現在、CVE-2025-67038に注目。Lantronix EDS5000のコードインジェクション脆弱性で、ルート権限のもとに任意のOSコマンドが実行される事例あり。注意が必要。
@Joe_Biden_ja
27 Jun 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Most people will see the headline. The real signal is what lantronix-eds5000-cve-2025-67038… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/6z47aE7VPr
@lucasverdan
26 Jun 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
lantronix-eds5000-cve-2025-67038-active-exploitation is not just a headline. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/lLwwd1KsRm
@fynn_JourX
26 Jun 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038 se explotó como zero-day desde el 5 de abril, semanas antes del patch. Forescout cree que alguien hizo reversing del parche del 20 de febrero. https://t.co/qccr8V6HSh
@NeoteoCom
26 Jun 2026
125 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
lantronix-eds5000-cve-2025-67038-active-exploitation is not just a headline. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://t.co/ctMUcuMFZT
@SocXAInvaders
26 Jun 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 Lantronix EDS5000 exploitation shows why edge device patch windows are… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Details → https://t.co/6z47aE7VPr
@lucasverdan
26 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. Lantronix EDS5000 exploitation shows why edge device patc… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Read → https://t.co/lLwwd1KsRm
@fynn_JourX
26 Jun 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, lantronix eds5000 exploitation shows why edge device patch wind… should move fast. CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command… 🔗 Details → https://t.co/ctMUcuMFZT
@SocXAInvaders
26 Jun 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA's deadline for the Lantronix EDS5000 vulnerability is today. CVE-2025-67038. CVSS 9.8. Actively exploited. The bug itself is almost embarrassingly simple: a username field gets concatenated directly into a shell command with no sanitization. Type the wrong username, run
@ByteDrop453
26 Jun 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warnt: Kritische Lantronix EDS5000-Lücke CVE-2025-67038 wird aktiv ausgenutzt CISA warnt vor CVE-2025-67038 (CVSS 9.8) in Lantronix EDS5000 Series. Die Lücke https://t.co/Q1sY34KmS4 https://t.co/h6w1zmNsQ8
@schoenfelderED
26 Jun 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ UPDATE - Forescout says CVE-2025-67038 was exploited as a zero-day. The Lantronix flaw was used against honeypots as early as April 5, weeks before BRIDGE:BREAK was publicly disclosed. Attackers may have reverse-engineered the Feb. 20 patch to build the exploit. Read: h
@TheHackersNews
26 Jun 2026
37623 Impressions
16 Retweets
62 Likes
9 Bookmarks
4 Replies
3 Quotes
A critical Lantronix flaw is now under active exploitation. CISA says CVE-2025-67038 affects EDS5000 Series devices and can let attackers run commands with root privileges. Federal civilian agencies have until June 26, 2026, to patch. https://t.co/10IVvh7ajQ
@ridwanseun12
26 Jun 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038に関する情報。Lantronix EDS5000では、コードインジェクションにより、攻撃者がroot権限で任意のOSコマンドを実行できる。XSSの恐れもあり。
@Joe_Biden_ja
26 Jun 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added CVE-2025-67038 in Lantronix EDS5000 devices to its KEV list on June 23, 2026, confirming active exploitation of an unauthenticated OS command injection vulnerability, NHS England reported. https://t.co/zEwHkMUMFt
@threatcluster
25 Jun 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Lantronix EDS5000 Command Injection (CVE-2025-67038) Exploited in the Wild, Now in CISA KEV #cybersecurity #infosec #threatintel https://t.co/AoXJP1xPJg
@zerodaywire
25 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Lantronix serial-to-IP converters are getting hit in the wild now. CVE-2025-67038 from the April BRIDGE:BREAK disclosure. If you're running OT gear with these boxes, patch or segment. https://t.co/sgRWuG6rNU
@elsontech
25 Jun 2026
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ CVE-2025-67038: Lantronix EDS5000 serial device server — code injection via unauthenticated web interface, now on CISA KEV. ICS/OT environments using these serial-to-IP gateways should patch or isolate immediately. https://t.co/1NcAogqaaO
@colibrisec
25 Jun 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
แจ้งเตือนช่องโหว่ Critical ใน Lantronix EDS5000 ถูกนำไปใช้โจมตี ขอให้ผู้ดูแลระบบเร่งอัปเดต Firmware ศูนย์ประสานการรักษา
@ThaiCERTByNCSA
25 Jun 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
แจ้งเตือนช่องโหว่ Critical ใน Lantronix EDS5000 ถูกนำไปใช้โจมตี ขอให้ผู้ดูแลระบบเร่งอัปเดต Firmware ศูนย์ประสานการรักษา
@ThaiCERTByNCSA
25 Jun 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
حذرت وكالة الأمن السيبراني الأمريكية من استغلال نشط للثغرة CVE-2025-67038 في أجهزة لانترونيكس EDS5000، ودعت إلى تطبيق التحديثات الأمنية بشكل عاجل. 📌 للتفاصيل الك
@ncnarabic
25 Jun 2026
65 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA alerts on CVE-2025-67038—a critical code injection flaw exploited in Lantronix EDS5000 devices. Federal agencies must patch by June 26, 2026. Assess your inventory and update now! #Lantronix #CISA #PatchNow #Cybersecurity #RemoteCodeExecution https://t.co/k63Pj63i6V
@SOCMinute
25 Jun 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are injecting OS commands through authentication parameters in Lantronix EDS5000 devices to gain root access (CVE-2025-67038). TRC analysis shows compromised devices serve as footholds for lateral movement across connected networks. Runtime segmentation helps contain
@aviatrixtrc
24 Jun 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA warns of active exploitation of CVE-2025-67038, a critical flaw in Lantronix EDS5000 devices. https://t.co/Y0mLtrDt8S
@f1tym1
24 Jun 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA warns CVE-2025-67038 (CVSS 9.8) in Lantronix EDS5000 is being actively exploited a code injection flaw letting attackers run root-privileged commands via unsanitized username input. FCEB agencies must patch by June 26, 2026.
@techepages
24 Jun 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A command injection flaw in Lantronix EDS5000 serial-to-Ethernet device servers hit CISA's KEV catalog yesterday. CVE-2025-67038, CVSS 9.8. Federal civilian agencies have until June 26 to patch. That's 48 hours. The mechanics are as clean as they get. The HTTP RPC module
@GoCocoaAI
24 Jun 2026
95 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
A critical Lantronix flaw is now under active exploitation. CISA says CVE-2025-67038 affects EDS5000 Series devices and can let attackers run commands with root privileges. Federal civilian agencies have until June 26, 2026, to patch. Learn more: https://t.co/oAxbINfejl https:
@TheHackersNews
24 Jun 2026
23845 Impressions
25 Retweets
67 Likes
7 Bookmarks
3 Replies
4 Quotes
🚨 CISA KEV Catalog Update June 2026 (status on 24.06.2026) - actively exploited vulnerabilities in the database: 🔹 Ubiquiti UniFi OS: CVE-2026-34908/34909/34910 (due 6/26) 🔹 Lantronix EDS5000: CVE-2025-67038 (due 6/26) 🔹 Splunk Enterprise: CVE-2026-20253 (due 6/21)
@techepages
24 Jun 2026
104 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Today’s CTI call: patch/exposure beats actor-label hunting. CISA added 4 actively exploited device/control-plane bugs to KEV: - Ubiquiti UniFi OS: CVE-2026-34908 / 34909 / 34910 - Lantronix EDS5000: CVE-2025-67038 Treat this as immediate asset inventory + management-plane
@alphahunt_io
24 Jun 2026
112 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
1 Quote
米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/23追加) 🛡CVE-2025-67038 ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/
@piyokango
24 Jun 2026
5530 Impressions
1 Retweet
6 Likes
2 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-67038: Lantronix EDS5000 HTTP RPC module Command Execution Critical Vulnerability Alert! Lantronix is affected by CVE-2025-67038. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/8CrY7rh8ah 🔍 Identify Targets via ZoomEye: Filter: https:
@zoomeye_team
24 Jun 2026
2017 Impressions
8 Retweets
18 Likes
6 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Jun 23) CVE-2025-67038 Lantronix EDS5000のコードインジェクション脆弱性 CVE-2026-34908 Ubiquiti UniFi OSの不適切なアクセ
@foxbook
24 Jun 2026
290 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 WARNING: Lantronix EDS5000 suffers critical code injection flaw CVE-2025-67038 allowing root-level OS command execution via username parameter. ⚡️ CISA added it to Known Exploited Vulnerabilities catalog with patch deadline June 26. Immediate mitigation required.
@ThreatPing
23 Jun 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、Lantronix EDS5000のCVE-2025-67038とUbiquiti UniFi OSのCVE-2026-34908~34910の4件を追加。対処期限はいずれも3日後の6/26。ランサム
@__kokumoto
23 Jun 2026
1045 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 CRITICAL: CVE-2025-67038 - Lantronix EDS5000 code injection flaw allows attackers to execute arbitrary OS commands as root via username parameter. CISA KEV listed. Patch immediately. #CVE #PatchNow https://t.co/focVviYfVg
@DFIR_Lab
23 Jun 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 4 new CISA KEV adds today CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2025-67038 https://t.co/0StDFCzdCI #boarnet #cybersecurity #cisakev #cve #threatintelligence #malware
@boarnetio
23 Jun 2026
63 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-67038 An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is d… https://t.co/40mJZpH0IG
@CVEnew
15 Mar 2026
194 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:*",
"matchCriteriaId": "BFA9E944-25EA-44A8-97EB-EF962EC155EE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*",
"matchCriteriaId": "04B4C755-3690-44B1-900A-71C5BEB4A1C0",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:*",
"matchCriteriaId": "CA2F9C4B-D268-4A78-A563-BB0169D2AD28",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B983DA3B-63DC-4981-A671-66A674234E80",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:*",
"matchCriteriaId": "A329F473-DB34-456E-B934-E47DCD7E2573",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*",
"matchCriteriaId": "86808903-C99D-4C74-A1D2-3E708B2074D8",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]