CVE-2025-67038
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
In plain language
AI Act nowCVE-2025-67038 is a critical command-injection flaw in Lantronix EDS5000 device firmware that lets an internet attacker run commands as the device’s root account during failed login attempts—small businesses should treat this as urgent and patch immediately.
CVE-2025-67038 is a command-injection vulnerability in the Lantronix EDS5000 HTTP RPC module where an unauthenticated attacker injects shell metacharacters via the username field during failed authentication, causing arbitrary OS command execution with root privileges; it is listed in CISA KEV and actively exploited.
What to do now
- Check whether you run or manage Lantronix EDS5032, EDS5008, or EDS5016 firmware based on Lantronix EDS5000, and note the exact firmware version.
- If the firmware is earlier than 2.2.0.0R1 (including 2.1.0.0R3), plan an upgrade to EDS5000 version 2.2.0.0R1 as your fix.
- If you cannot upgrade right away, immediately restrict access so the device is not reachable from the internet (allow only required internal networks/VPNs).
- After upgrade, verify the device is functioning normally and continue to monitor logs for repeated failed authentication attempts and any signs of unexpected command/log behavior.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warningen-us·SecurityWeek· Exploited EDS5000 ics-ot-iot
- CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploiteden·The Hacker News· Exploited EDS5000 rce
- CISA warns of max severity Ubiquiti flaws exploited in attacksen-us·BleepingComputer· Exploited UniFi OS rce
- Critical Ubiquiti Vulnerabilities in Attackers’ Crosshairsen-us·SecurityWeek· Exploited UniFi OS rce
- CISA Adds Four Exploited UniFi OS and Lantronix Flaws to KEV Catalogen-us·Daily CyberSecurity (securityonline.info)· Exploited Ubiquiti UniFi OS ics-ot-iot
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-67038 and every CVE in our database. Create a free account — no credit card required.
Create Free Account