Vulnerability intelligence
CVE-2025-67038
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
14%
Riskier than 96% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-23
Remediation
unknown
Federal deadline 2026-06-26
11 articles across 5 outlets · first covered Jun 23, 2026 · latest Jun 25, 2026
Coverage timeline
-
Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warningwww.securityweek.com · Jun 25, 2026
-
CISA urges patching as hackers exploit critical Ubiquiti flawswww.securityweek.com · Jun 24, 2026
-
CISA flags Ubiquiti, Lantronix flaws; urges US patch by June 2026securityaffairs.com · Jun 24, 2026
-
SmartRAT ClickFix targets Brazilian banks with AI spoofed domainssecurityonline.info · Jun 24, 2026
-
CVE-2025-67038 exploit seen in Lantronix, Ubiquiti devicessecurityonline.info · Jun 24, 2026
-
Lantronix, UniFi flaws surface as Outlook Mac reply glitch seensecurityonline.info · Jun 24, 2026
-
Google Search Now Saves Your Uploaded Media to Train AIsecurityonline.info · Jun 24, 2026
-
Flaw in AVer PTC500S cameras allows remote code executionsecurityonline.info · Jun 24, 2026
-
CISA Adds Four Exploited UniFi OS and Lantronix Flaws to KEV Catalogsecurityonline.info · Jun 24, 2026
-
Lantronix EDS5000 Command Injection Flaw Under Active Attackwww.cisa.gov · Jun 23, 2026
-
Lantronix EDS5000 Command Injection Flaw Under Active Attackcisa.gov · Jun 23, 2026