Executive brief
Lantronix EDS5000 series device servers, which are used to connect industrial equipment to networks, contain a critical security flaw. An attacker can take full control of the device by providing a specially crafted username during a failed login attempt. This could lead to unauthorized access to sensitive industrial data, disruption of operations, or a foothold for further attacks on the corporate network.
Technical details
An OS command injection vulnerability exists in the HTTP RPC module of Lantronix EDS5000 firmware version 2.1.0.0R3. The vulnerability occurs when the system handles failed authentication attempts; the provided username is directly concatenated into a shell command used for logging without prior sanitization. A remote, unauthenticated attacker can exploit this by submitting a malicious username containing shell metacharacters. Successful exploitation results in arbitrary command execution with root-level privileges. Lantronix has released firmware version 2.2.0.0R1 to address this issue.
Affected products
- Lantronix EDS5000 firmware 2.1.0.0R3
- Lantronix EDS5008 2.1.0.0R3
- Lantronix EDS5016 2.1.0.0R3
- Lantronix EDS5032 2.1.0.0R3
Timeline
- 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
- 2026-03-11: disclosed: CVE-2025-67038 published
- 2026-03-11: patched: Vendor released firmware version 2.2.0.0R1