CVE-2025-67038
Lantronix EDS5000 Code Injection Vulnerability
Description
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Description as published by the source, in English.
Key facts
- Published
- 2026-03-11
- Last modified
- 2026-09-08
- Assigned by
- ics-cert@hq.dhs.gov
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:- Scored by
- ics-cert@hq.dhs.gov
- Probability of exploitation
-
14.3 %
higher than 96 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-06-23, with a remediation deadline of 2026-06-26 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| Lantronix | E213f102s | all versions listed | Not affected |
| Lantronix | E213f102s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E214f002s | all versions listed | Not affected |
| Lantronix | E214f002s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E214f00cs | all versions listed | Not affected |
| Lantronix | E214f00cs Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E214g000s | all versions listed | Not affected |
| Lantronix | E214g000s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E214g001s | all versions listed | Not affected |
| Lantronix | E214g001s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E218f004s | all versions listed | Not affected |
| Lantronix | E218f004s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E218g107s | all versions listed | Not affected |
| Lantronix | E218g107s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E228g002s | all versions listed | Not affected |
| Lantronix | E228g002s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E228g004s | all versions listed | Not affected |
| Lantronix | E228g004s Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E228g00cb28 | all versions listed | Not affected |
| Lantronix | E228g00cb28 Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | E228g00cs | all versions listed | Not affected |
| Lantronix | E228g00cs Firmware | < 3.21.0.0R1 | Affected |
| Lantronix | Eds5008 | all versions listed | Not affected |
| Lantronix | Eds5008 Firmware | < 2.2.0.0r1 | Affected |
| Lantronix | Eds5016 | all versions listed | Not affected |
| Lantronix | Eds5016 Firmware | < 2.2.0.0r1 | Affected |
| Lantronix | Eds5032 | all versions listed | Not affected |
| Lantronix | Eds5032 Firmware | < 2.2.0.0r1 | Affected |
| Lantronix | G526gp12s | all versions listed | Not affected |
| Lantronix | G526gp12s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G526gp17s | all versions listed | Not affected |
| Lantronix | G526gp17s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G526gp1as | all versions listed | Not affected |
| Lantronix | G526gp1as Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G526gp1asg | all versions listed | Not affected |
| Lantronix | G526gp1asg Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G526gp1cs | all versions listed | Not affected |
| Lantronix | G526gp1cs Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G527gp22s | all versions listed | Not affected |
| Lantronix | G527gp22s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G527gp27s | all versions listed | Not affected |
| Lantronix | G527gp27s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G527gp2as | all versions listed | Not affected |
| Lantronix | G527gp2as Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G527gp2asg | all versions listed | Not affected |
| Lantronix | G527gp2asg Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G528gp2fs | all versions listed | Not affected |
| Lantronix | G528gp2fs Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G528gp2fsg | all versions listed | Not affected |
| Lantronix | G528gp2fsg Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | G528gp2fsgc | all versions listed | Not affected |
| Lantronix | G528gp2fsgc Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | X300f202s | all versions listed | Not affected |
| Lantronix | X300f202s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | X303f202s | all versions listed | Not affected |
| Lantronix | X303f202s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | X304g000s | all versions listed | Not affected |
| Lantronix | X304g000s Firmware | < 2.6.0.4R6 | Affected |
| Lantronix | X304g002s | all versions listed | Not affected |
| Lantronix | X304g002s Firmware | < 2.6.0.4R6 | Affected |
Weakness type
-
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS …
-
CWE-94: Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or b…
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1027.006: HTML Smuggling
- T1027.009: Embedded Payloads
- T1564.009: Resource Forking
References
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-pol…
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
Related at Berigo
Articles
-
Nine advisories in one day, from brake computers to ship transponders
Mentions this CVE
2026-08-25
CISA published seven new ICS advisories on 25 August 2026 and revised two older ones the same day. Five of the nine carry a top CVSS v3.1 score of 9.…
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.