Record summary

CVE-2025-67038 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC. CISA lists CVE-2025-67038 in KEV.

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Jun 23, 2026 · CISA
VulnCheck KEV
Listed · Jun 23, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 23, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Repository PoCs

GitHubHORKimhab/CVE-2026-42055Repository PoCby HORKimhabStars: 0Not analyzed3 files

5.3 KiB · linked to 14 vulnerabilities

GitHub

PoC details

References

5