Junglewise Threat Intelligence

CVE-2025-67038: Lantronix EDS5000 OS command injection in HTTP RPC module

CVE-2025-67038 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-11

Technologies: Lantronix Eds5016, Lantronix Eds5008 Firmware, Lantronix Eds5016 Firmware, Lantronix EDS5000 firmware, Lantronix Eds5032 Firmware, Lantronix Eds5008, Lantronix Eds5032. Vendors: Lantronix.

Executive brief

Lantronix EDS5000 series device servers, which are used to connect industrial equipment to networks, contain a critical security flaw. An attacker can take full control of the device by providing a specially crafted username during a failed login attempt. This could lead to unauthorized access to sensitive industrial data, disruption of operations, or a foothold for further attacks on the corporate network.

Technical details

An OS command injection vulnerability exists in the HTTP RPC module of Lantronix EDS5000 firmware version 2.1.0.0R3. The vulnerability occurs when the system handles failed authentication attempts; the provided username is directly concatenated into a shell command used for logging without prior sanitization. A remote, unauthenticated attacker can exploit this by submitting a malicious username containing shell metacharacters. Successful exploitation results in arbitrary command execution with root-level privileges. Lantronix has released firmware version 2.2.0.0R1 to address this issue.

Affected products

  • Lantronix EDS5000 firmware 2.1.0.0R3
  • Lantronix EDS5008 2.1.0.0R3
  • Lantronix EDS5016 2.1.0.0R3
  • Lantronix EDS5032 2.1.0.0R3

Timeline

  • 2026-03-10: advisory: CISA ICS Advisory ICSA-26-069-02 published
  • 2026-03-11: disclosed: CVE-2025-67038 published
  • 2026-03-11: patched: Vendor released firmware version 2.2.0.0R1

References

Related threats