CVE-2025-67038
CRITICAL KEVLantronix EDS5000 2.1.0.0R3 - Command Injection
Title source: llmExploitation Summary
CVE-2025-67038 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added June 23, 2026. EIP tracks 2 public exploits from researchers including HORKimhab.
AI-analyzed exploit summary The repository contains a technical writeup describing a command injection vulnerability in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module unsafely concatenates user input (username) into a shell command, allowing arbitrary command execution with root privileges.
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Exploits (2)
The repository contains a technical writeup describing a command injection vulnerability in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module unsafely concatenates user input (username) into a shell command, allowing arbitrary command execution with root privileges.
The repository lacks actual exploit code or technical details about CVE-2025-67038, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H