logo

Critical Vulnerability CVE-2025-67038 Exploited in Lantronix Devices

ID: 4aa806e3-2081-56bd-8bd4-64e2b6ee45ff

STIX ID: report--4aa806e3-2081-56bd-8bd4-64e2b6ee45ff

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

CVE-2025-67038 is an unauthenticated OS command injection vulnerability impacting Lantronix EDS5000 and related devices (e.g., EDS3000PS) that can enable arbitrary root command execution on industrial automation systems. CISA added the flaw to its Known Exploited Vulnerabilities list on June 23, 2026, a public proof-of-concept was released on June 25, 2026, and Lantronix has issued firmware updates; affected organizations are urged to apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.