{"id":"CVE-2025-67038","title":"An issue was discovered in Lantronix EDS5000 2.1.0.0R3","summary":"An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This al…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78","CWE-94"],"vendor":"lantronix","product":"eds5008_firmware","affected":["eds5008_firmware < 2.2.0.0r1","eds5016_firmware < 2.2.0.0r1","eds5032_firmware < 2.2.0.0r1","g526gp12s_firmware < 2.6.0.4R6","g526gp17s_firmware < 2.6.0.4R6","g526gp1cs_firmware < 2.6.0.4R6","g526gp1asg_firmware < 2.6.0.4R6","g526gp1as_firmware < 2.6.0.4R6","g527gp22s_firmware < 2.6.0.4R6","g527gp27s_firmware < 2.6.0.4R6","g527gp2as_firmware < 2.6.0.4R6","g527gp2asg_firmware < 2.6.0.4R6","g528gp2fs_firmware < 2.6.0.4R6","g528gp2fsg_firmware < 2.6.0.4R6","g528gp2fsgc_firmware < 2.6.0.4R6","x300f202s_firmware < 2.6.0.4R6","x303f202s_firmware < 2.6.0.4R6","x304g00as_firmware < 2.6.0.4R6","x304g000s_firmware < 2.6.0.4R6","x304g002s_firmware < 2.6.0.4R6","x304g007s_firmware < 2.6.0.4R6","x304g00cs_firmware < 2.6.0.4R6","e228g002s_firmware < 3.21.0.0R1","e228g004s_firmware < 3.21.0.0R1","e228g00cb28_firmware < 3.21.0.0R1","e228g00cs_firmware < 3.21.0.0R1","e213f102s_firmware < 3.21.0.0R1","e214f002s_firmware < 3.21.0.0R1","e214f00cs_firmware < 3.21.0.0R1","e214g000s_firmware < 3.21.0.0R1","e214g001s_firmware < 3.21.0.0R1","e218f004s_firmware < 3.21.0.0R1","e218g107s_firmware < 3.21.0.0R1"],"patched":["eds5008_firmware 2.2.0.0r1","eds5016_firmware 2.2.0.0r1","eds5032_firmware 2.2.0.0r1","g526gp12s_firmware 2.6.0.4R6","g526gp17s_firmware 2.6.0.4R6","g526gp1cs_firmware 2.6.0.4R6","g526gp1asg_firmware 2.6.0.4R6","g526gp1as_firmware 2.6.0.4R6","g527gp22s_firmware 2.6.0.4R6","g527gp27s_firmware 2.6.0.4R6","g527gp2as_firmware 2.6.0.4R6","g527gp2asg_firmware 2.6.0.4R6","g528gp2fs_firmware 2.6.0.4R6","g528gp2fsg_firmware 2.6.0.4R6","g528gp2fsgc_firmware 2.6.0.4R6","x300f202s_firmware 2.6.0.4R6","x303f202s_firmware 2.6.0.4R6","x304g00as_firmware 2.6.0.4R6","x304g000s_firmware 2.6.0.4R6","x304g002s_firmware 2.6.0.4R6","x304g007s_firmware 2.6.0.4R6","x304g00cs_firmware 2.6.0.4R6","e228g002s_firmware 3.21.0.0R1","e228g004s_firmware 3.21.0.0R1","e228g00cb28_firmware 3.21.0.0R1","e228g00cs_firmware 3.21.0.0R1","e213f102s_firmware 3.21.0.0R1","e214f002s_firmware 3.21.0.0R1","e214f00cs_firmware 3.21.0.0R1","e214g000s_firmware 3.21.0.0R1","e214g001s_firmware 3.21.0.0R1","e218f004s_firmware 3.21.0.0R1","e218g107s_firmware 3.21.0.0R1"],"published":"2026-03-11","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:00:57.803","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-67038","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"http://eds5000.com","label":"cve@mitre.org"},{"url":"http://lantronix.com","label":"cve@mitre.org"}],"tags":["nvd","kev","in-the-wild","exploit-available","cve.org"],"epss":0.1926,"epssPercentile":0.9727,"kev":true,"kevDateAdded":"2026-06-23","kevDueDate":"2026-06-26","kevRansomware":false,"exploited":true,"exploits":{"github":1,"githubRepos":["https://github.com/HORKimhab/CVE-2025-67038"],"checkedAt":"2026-09-21T15:27:46.133Z"},"exploitAvailable":true,"ssvc":{"exploitation":"active","automatable":"yes","technicalImpact":"total","timestamp":"2026-06-24T03:55:55.997634Z"},"ingestedAt":"2026-06-29T13:24:34.804Z","slug":"CVE-2025-67038","body":"## Overview\n\nAn issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.\n\n## Affected\n\n- `eds5008_firmware < 2.2.0.0r1`\n- `eds5016_firmware < 2.2.0.0r1`\n- `eds5032_firmware < 2.2.0.0r1`\n- `g526gp12s_firmware < 2.6.0.4R6`\n- `g526gp17s_firmware < 2.6.0.4R6`\n- `g526gp1cs_firmware < 2.6.0.4R6`\n- `g526gp1asg_firmware < 2.6.0.4R6`\n- `g526gp1as_firmware < 2.6.0.4R6`\n- `g527gp22s_firmware < 2.6.0.4R6`\n- `g527gp27s_firmware < 2.6.0.4R6`\n- `g527gp2as_firmware < 2.6.0.4R6`\n- `g527gp2asg_firmware < 2.6.0.4R6`\n- `g528gp2fs_firmware < 2.6.0.4R6`\n- `g528gp2fsg_firmware < 2.6.0.4R6`\n- `g528gp2fsgc_firmware < 2.6.0.4R6`\n- `x300f202s_firmware < 2.6.0.4R6`\n- `x303f202s_firmware < 2.6.0.4R6`\n- `x304g00as_firmware < 2.6.0.4R6`\n- `x304g000s_firmware < 2.6.0.4R6`\n- `x304g002s_firmware < 2.6.0.4R6`\n- `x304g007s_firmware < 2.6.0.4R6`\n- `x304g00cs_firmware < 2.6.0.4R6`\n- `e228g002s_firmware < 3.21.0.0R1`\n- `e228g004s_firmware < 3.21.0.0R1`\n- `e228g00cb28_firmware < 3.21.0.0R1`\n- `e228g00cs_firmware < 3.21.0.0R1`\n- `e213f102s_firmware < 3.21.0.0R1`\n- `e214f002s_firmware < 3.21.0.0R1`\n- `e214f00cs_firmware < 3.21.0.0R1`\n- `e214g000s_firmware < 3.21.0.0R1`\n- `e214g001s_firmware < 3.21.0.0R1`\n- `e218f004s_firmware < 3.21.0.0R1`\n- `e218g107s_firmware < 3.21.0.0R1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `eds5008_firmware 2.2.0.0r1`\n- `eds5016_firmware 2.2.0.0r1`\n- `eds5032_firmware 2.2.0.0r1`\n- `g526gp12s_firmware 2.6.0.4R6`\n- `g526gp17s_firmware 2.6.0.4R6`\n- `g526gp1cs_firmware 2.6.0.4R6`\n- `g526gp1asg_firmware 2.6.0.4R6`\n- `g526gp1as_firmware 2.6.0.4R6`\n- `g527gp22s_firmware 2.6.0.4R6`\n- `g527gp27s_firmware 2.6.0.4R6`\n- `g527gp2as_firmware 2.6.0.4R6`\n- `g527gp2asg_firmware 2.6.0.4R6`\n- `g528gp2fs_firmware 2.6.0.4R6`\n- `g528gp2fsg_firmware 2.6.0.4R6`\n- `g528gp2fsgc_firmware 2.6.0.4R6`\n- `x300f202s_firmware 2.6.0.4R6`\n- `x303f202s_firmware 2.6.0.4R6`\n- `x304g00as_firmware 2.6.0.4R6`\n- `x304g000s_firmware 2.6.0.4R6`\n- `x304g002s_firmware 2.6.0.4R6`\n- `x304g007s_firmware 2.6.0.4R6`\n- `x304g00cs_firmware 2.6.0.4R6`\n- `e228g002s_firmware 3.21.0.0R1`\n- `e228g004s_firmware 3.21.0.0R1`\n- `e228g00cb28_firmware 3.21.0.0R1`\n- `e228g00cs_firmware 3.21.0.0R1`\n- `e213f102s_firmware 3.21.0.0R1`\n- `e214f002s_firmware 3.21.0.0R1`\n- `e214f00cs_firmware 3.21.0.0R1`\n- `e214g000s_firmware 3.21.0.0R1`\n- `e214g001s_firmware 3.21.0.0R1`\n- `e218f004s_firmware 3.21.0.0R1`\n- `e218g107s_firmware 3.21.0.0R1`","depth":"hadal","depthScore":83,"depthScoreParts":{"impact":53.9,"likelihood":3.9,"exploitation":25,"ransomware":0},"changes":[{"seq":4899,"id":"CVE-2025-67038","ts":1788887215356,"field":"exploit_available","old":"false","new":"true"},{"seq":3782,"id":"CVE-2025-67038","ts":1788886334901,"field":"exploit_available","old":"true","new":"false"},{"seq":2627,"id":"CVE-2025-67038","ts":1788883013134,"field":"exploit_available","old":"false","new":"true"},{"seq":1656,"id":"CVE-2025-67038","ts":1788882417492,"field":"exploit_available","old":"true","new":"false"},{"seq":764,"id":"CVE-2025-67038","ts":1788881850805,"field":"exploit_available","old":"false","new":"true"},{"seq":225,"id":"CVE-2025-67038","ts":1788642743140,"field":"epss","old":"0.15667","new":"0.21985"},{"seq":82,"id":"CVE-2025-67038","ts":1784920462562,"field":"epss","old":"0.00889","new":"0.1432"}]}