CVE-2025-67038: Lantronix EDS5000 OS Command Injection Vulnerability
ID: 86955171-cafb-56c8-a061-4020b5073d2b
STIX ID: report--86955171-cafb-56c8-a061-4020b5073d2b
Feed Name: CosmicBytez Labs
### Executive Summary A critical OS command injection (CVE-2025-67038) affecting Lantronix EDS5000 serial device servers permits unauthenticated, network-accessible root remote command execution via unsanitized username input; CISA added the CVE to its Known Exploited Vulnerabilities catalog (June 23, 2026), indicating active exploitation. The advisory provides affected contexts (OT/ICS), attack primitives, detection examples (malicious POST with shell metacharacters), network mitigation examples, and recommends immediate patching, isolation, and logging/audit actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
