Critical Vulnerability CVE-2025-67038 Exploited in Lantronix Devices
ID: 4aa806e3-2081-56bd-8bd4-64e2b6ee45ff
STIX ID: report--4aa806e3-2081-56bd-8bd4-64e2b6ee45ff
Feed Name: ThreatCluster
Threat Score
CVE-2025-67038 is an unauthenticated OS command injection vulnerability impacting Lantronix EDS5000 and related devices (e.g., EDS3000PS) that can enable arbitrary root command execution on industrial automation systems. CISA added the flaw to its Known Exploited Vulnerabilities list on June 23, 2026, a public proof-of-concept was released on June 25, 2026, and Lantronix has issued firmware updates; affected organizations are urged to apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
