CVE-2025-67038

CRITICAL KEV

Lantronix EDS5000 2.1.0.0R3 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2025-67038 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 23, 2026. EIP tracks 2 public exploits from researchers including HORKimhab.

AI-analyzed exploit summary The repository contains a technical writeup describing a command injection vulnerability in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module unsafely concatenates user input (username) into a shell command, allowing arbitrary command execution with root privileges.

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Exploits (2)

github WRITEUP
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2025/67xxx/CVE-2025-67038.md

The repository contains a technical writeup describing a command injection vulnerability in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module unsafely concatenates user input (username) into a shell command, allowing arbitrary command execution with root privileges.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Lantronix EDS5000 2.1.0.0R3
No auth needed
Prerequisites: network access to the target device
mistral-large-3 · analyzed Jun 27, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2025-67038

The repository lacks actual exploit code or technical details about CVE-2025-67038, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 25, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.0089
EPSS Percentile 55.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-06-23
VulnCheck KEV 2026-06-23
ENISA EUVD EUVD-2025-208587
CWE
CWE-94
Status published
Products (6)
lantronix/eds5008_firmware 2.1.0.0 r3
lantronix/eds5008_firmware 2.1.0.0r3
lantronix/eds5016_firmware 2.1.0.0 r3
lantronix/eds5016_firmware 2.1.0.0r3
lantronix/eds5032_firmware 2.1.0.0 r3
lantronix/eds5032_firmware 2.1.0.0r3
Published Mar 11, 2026
KEV Added Jun 23, 2026
Tracked Since Mar 12, 2026