logo

CVE-2025-67038: Lantronix EDS5000 OS Command Injection Vulnerability

ID: 86955171-cafb-56c8-a061-4020b5073d2b

STIX ID: report--86955171-cafb-56c8-a061-4020b5073d2b

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

### Executive Summary A critical OS command injection (CVE-2025-67038) affecting Lantronix EDS5000 serial device servers permits unauthenticated, network-accessible root remote command execution via unsanitized username input; CISA added the CVE to its Known Exploited Vulnerabilities catalog (June 23, 2026), indicating active exploitation. The advisory provides affected contexts (OT/ICS), attack primitives, detection examples (malicious POST with shell metacharacters), network mitigation examples, and recommends immediate patching, isolation, and logging/audit actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.