www.cisa.gov 6/23/2026, 7:47:58 PM · external

Lantronix EDS5000 Command Injection Flaw Under Active Attack

Developing story vulnerability 2 articles tracked
Lantronix EDS5000 command injection flaw (CVE-2025-67038) under active attack
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a crucial resource for cybersecurity professionals to identify vulnerabilities that have been actively exploited. Organizations are encouraged to utilize this catalog for effective vulnerability management. The page includes details on the Lantronix EDS5000 vulnerability (CVE-2025-67038), highlighting its potential for code injection attacks that can execute commands with root privileges.

It also provides action recommendations for mitigation, compliance with security directives (BOD 26-04), and links to resources such as the catalog in various formats (CSV, JSON) and firmware updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline