CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability
Published Mar 11, 2026
·Updated
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Other sources
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
— CISA
Affected Software
8 affected components
Lantronix EDS5000
Lantronix EDS5000
All of the following
Lantronix Eds5032 Firmware=2.1.0.0r3
Lantronix Eds5032
All of the following
Lantronix Eds5008 Firmware=2.1.0.0r3
Lantronix Eds5008
All of the following
Lantronix Eds5016 Firmware=2.1.0.0r3
Lantronix Eds5016
Event History
Mar 11, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Jun 23, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Jun 24, 2026
News Published
via BleepingComputer·02:35 PM
News Published
via BleepingComputer·02:37 PM