CVE Details

CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability
Published: 2026-06-23 CVSS: 9.8 CRITICAL Product: Lantronix EDS5000 Due Date: 2026-06-26

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

No GitHub PoC data.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
cveMetadata > state PUBLISHED
cveMetadata > cveId CVE-2025-67038
cveMetadata > assignerOrgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
cveMetadata > assignerShortName mitre
cveMetadata > dateUpdated 2026-06-23T17:51:01.956Z
cveMetadata > dateReserved 2025-12-08T00:00:00.000Z
cveMetadata > datePublished 2026-03-11T00:00:00.000Z
containers > cna > providerMetadata > orgId 8254265b-2729-46b6-b9e3-3dfca2d5bfca
containers > cna > providerMetadata > shortName mitre
containers > cna > providerMetadata > dateUpdated 2026-03-11T16:12:30.541Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
containers > cna > affected > 0 > vendor n/a
containers > cna > affected > 0 > product n/a
containers > cna > affected > 0 > versions > 0 > version n/a
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > references > 0 > url http://lantronix.com
containers > cna > references > 1 > url http://eds5000.com
containers > cna > references > 2 > url https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
containers > cna > problemTypes > 0 > descriptions > 0 > type text
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > description n/a
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > cweId CWE-94
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > description CWE-94 Improper Control of Generation of Code ('Code Injection')
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 9.8
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-06-23T17:50:04.910214Z
containers > adp > 0 > metrics > 1 > other > content > id CVE-2025-67038
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-06-23T17:51:01.956Z
dataVersion 5.2