All CVEs
Vulnerability intelligence

CVE-2025-67038

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
14%
Riskier than 96% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-23
Remediation
unknown
Federal deadline 2026-06-26
NVD entry PoC / advisory CISA KEV

11 articles across 5 outlets · first covered Jun 23, 2026 · latest Jun 25, 2026

Coverage timeline