THREAT OPS › CVEs › CVE-2025-67038
CVE-2025-67038 — Lantronix EDS5000 Code Injection Vulnerability
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Vulnerability details
- Affected productsEDS5000
- KEV remediation due2026-06-26
Related reporting
- [NVD] CVE-2025-67038 (CRITICAL 9.8) — An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commannvd
- [CISA KEV] CVE-2025-67038 — Lantronix EDS5000: Lantronix EDS5000 Code Injection Vulnerabilitycisa_kev
- June 2026 CVE Landscaperecordedfuture