---
id: CVE-2025-67038
title: An issue was discovered in Lantronix EDS5000 2.1.0.0R3
summary: >-
  An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module
  executes a shell command to write logs when user's authentication fails. The
  username is directly concatenated with the command without any sanitization.
  This al…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-94
vendor: lantronix
product: eds5008_firmware
affected:
  - eds5008_firmware < 2.2.0.0r1
  - eds5016_firmware < 2.2.0.0r1
  - eds5032_firmware < 2.2.0.0r1
  - g526gp12s_firmware < 2.6.0.4R6
  - g526gp17s_firmware < 2.6.0.4R6
  - g526gp1cs_firmware < 2.6.0.4R6
  - g526gp1asg_firmware < 2.6.0.4R6
  - g526gp1as_firmware < 2.6.0.4R6
  - g527gp22s_firmware < 2.6.0.4R6
  - g527gp27s_firmware < 2.6.0.4R6
  - g527gp2as_firmware < 2.6.0.4R6
  - g527gp2asg_firmware < 2.6.0.4R6
  - g528gp2fs_firmware < 2.6.0.4R6
  - g528gp2fsg_firmware < 2.6.0.4R6
  - g528gp2fsgc_firmware < 2.6.0.4R6
  - x300f202s_firmware < 2.6.0.4R6
  - x303f202s_firmware < 2.6.0.4R6
  - x304g00as_firmware < 2.6.0.4R6
  - x304g000s_firmware < 2.6.0.4R6
  - x304g002s_firmware < 2.6.0.4R6
  - x304g007s_firmware < 2.6.0.4R6
  - x304g00cs_firmware < 2.6.0.4R6
  - e228g002s_firmware < 3.21.0.0R1
  - e228g004s_firmware < 3.21.0.0R1
  - e228g00cb28_firmware < 3.21.0.0R1
  - e228g00cs_firmware < 3.21.0.0R1
  - e213f102s_firmware < 3.21.0.0R1
  - e214f002s_firmware < 3.21.0.0R1
  - e214f00cs_firmware < 3.21.0.0R1
  - e214g000s_firmware < 3.21.0.0R1
  - e214g001s_firmware < 3.21.0.0R1
  - e218f004s_firmware < 3.21.0.0R1
  - e218g107s_firmware < 3.21.0.0R1
patched:
  - eds5008_firmware 2.2.0.0r1
  - eds5016_firmware 2.2.0.0r1
  - eds5032_firmware 2.2.0.0r1
  - g526gp12s_firmware 2.6.0.4R6
  - g526gp17s_firmware 2.6.0.4R6
  - g526gp1cs_firmware 2.6.0.4R6
  - g526gp1asg_firmware 2.6.0.4R6
  - g526gp1as_firmware 2.6.0.4R6
  - g527gp22s_firmware 2.6.0.4R6
  - g527gp27s_firmware 2.6.0.4R6
  - g527gp2as_firmware 2.6.0.4R6
  - g527gp2asg_firmware 2.6.0.4R6
  - g528gp2fs_firmware 2.6.0.4R6
  - g528gp2fsg_firmware 2.6.0.4R6
  - g528gp2fsgc_firmware 2.6.0.4R6
  - x300f202s_firmware 2.6.0.4R6
  - x303f202s_firmware 2.6.0.4R6
  - x304g00as_firmware 2.6.0.4R6
  - x304g000s_firmware 2.6.0.4R6
  - x304g002s_firmware 2.6.0.4R6
  - x304g007s_firmware 2.6.0.4R6
  - x304g00cs_firmware 2.6.0.4R6
  - e228g002s_firmware 3.21.0.0R1
  - e228g004s_firmware 3.21.0.0R1
  - e228g00cb28_firmware 3.21.0.0R1
  - e228g00cs_firmware 3.21.0.0R1
  - e213f102s_firmware 3.21.0.0R1
  - e214f002s_firmware 3.21.0.0R1
  - e214f00cs_firmware 3.21.0.0R1
  - e214g000s_firmware 3.21.0.0R1
  - e214g001s_firmware 3.21.0.0R1
  - e218f004s_firmware 3.21.0.0R1
  - e218g107s_firmware 3.21.0.0R1
published: '2026-03-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:00:57.803'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67038'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02'
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'http://eds5000.com'
    label: cve@mitre.org
  - url: 'http://lantronix.com'
    label: cve@mitre.org
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.1926
epssPercentile: 0.97245
kev: true
kevDateAdded: '2026-06-23'
kevDueDate: '2026-06-26'
kevRansomware: false
exploited: true
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/HORKimhab/CVE-2025-67038'
  checkedAt: '2026-09-26T09:05:36.188Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-06-24T03:55:55.997634Z'
ingestedAt: '2026-06-29T13:24:34.804Z'
---

## Overview

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

## Affected

- `eds5008_firmware < 2.2.0.0r1`
- `eds5016_firmware < 2.2.0.0r1`
- `eds5032_firmware < 2.2.0.0r1`
- `g526gp12s_firmware < 2.6.0.4R6`
- `g526gp17s_firmware < 2.6.0.4R6`
- `g526gp1cs_firmware < 2.6.0.4R6`
- `g526gp1asg_firmware < 2.6.0.4R6`
- `g526gp1as_firmware < 2.6.0.4R6`
- `g527gp22s_firmware < 2.6.0.4R6`
- `g527gp27s_firmware < 2.6.0.4R6`
- `g527gp2as_firmware < 2.6.0.4R6`
- `g527gp2asg_firmware < 2.6.0.4R6`
- `g528gp2fs_firmware < 2.6.0.4R6`
- `g528gp2fsg_firmware < 2.6.0.4R6`
- `g528gp2fsgc_firmware < 2.6.0.4R6`
- `x300f202s_firmware < 2.6.0.4R6`
- `x303f202s_firmware < 2.6.0.4R6`
- `x304g00as_firmware < 2.6.0.4R6`
- `x304g000s_firmware < 2.6.0.4R6`
- `x304g002s_firmware < 2.6.0.4R6`
- `x304g007s_firmware < 2.6.0.4R6`
- `x304g00cs_firmware < 2.6.0.4R6`
- `e228g002s_firmware < 3.21.0.0R1`
- `e228g004s_firmware < 3.21.0.0R1`
- `e228g00cb28_firmware < 3.21.0.0R1`
- `e228g00cs_firmware < 3.21.0.0R1`
- `e213f102s_firmware < 3.21.0.0R1`
- `e214f002s_firmware < 3.21.0.0R1`
- `e214f00cs_firmware < 3.21.0.0R1`
- `e214g000s_firmware < 3.21.0.0R1`
- `e214g001s_firmware < 3.21.0.0R1`
- `e218f004s_firmware < 3.21.0.0R1`
- `e218g107s_firmware < 3.21.0.0R1`

## Remediation

Upgrade past the affected range:

- `eds5008_firmware 2.2.0.0r1`
- `eds5016_firmware 2.2.0.0r1`
- `eds5032_firmware 2.2.0.0r1`
- `g526gp12s_firmware 2.6.0.4R6`
- `g526gp17s_firmware 2.6.0.4R6`
- `g526gp1cs_firmware 2.6.0.4R6`
- `g526gp1asg_firmware 2.6.0.4R6`
- `g526gp1as_firmware 2.6.0.4R6`
- `g527gp22s_firmware 2.6.0.4R6`
- `g527gp27s_firmware 2.6.0.4R6`
- `g527gp2as_firmware 2.6.0.4R6`
- `g527gp2asg_firmware 2.6.0.4R6`
- `g528gp2fs_firmware 2.6.0.4R6`
- `g528gp2fsg_firmware 2.6.0.4R6`
- `g528gp2fsgc_firmware 2.6.0.4R6`
- `x300f202s_firmware 2.6.0.4R6`
- `x303f202s_firmware 2.6.0.4R6`
- `x304g00as_firmware 2.6.0.4R6`
- `x304g000s_firmware 2.6.0.4R6`
- `x304g002s_firmware 2.6.0.4R6`
- `x304g007s_firmware 2.6.0.4R6`
- `x304g00cs_firmware 2.6.0.4R6`
- `e228g002s_firmware 3.21.0.0R1`
- `e228g004s_firmware 3.21.0.0R1`
- `e228g00cb28_firmware 3.21.0.0R1`
- `e228g00cs_firmware 3.21.0.0R1`
- `e213f102s_firmware 3.21.0.0R1`
- `e214f002s_firmware 3.21.0.0R1`
- `e214f00cs_firmware 3.21.0.0R1`
- `e214g000s_firmware 3.21.0.0R1`
- `e214g001s_firmware 3.21.0.0R1`
- `e218f004s_firmware 3.21.0.0R1`
- `e218g107s_firmware 3.21.0.0R1`
