eds5000.com
http://eds5000.com/ CVE-2025-67038
CRITICALCISA KEV
Lantronix EDS5000 Code Injection Vulnerability
Record summary
CVE-2025-67038 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC. CISA lists CVE-2025-67038 in KEV.
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Jun 23, 2026 · CISA
- VulnCheck KEV
- Listed · Jun 23, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EDS5000Browse Lantronix / EDS5000 | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubHORKimhab/CVE-2026-42055Repository PoCby HORKimhabStars: 0Not analyzed3 files
References
5lantronix.com
http://lantronix.com/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-67038 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038 cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02