An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Is CVE-2025-67038 exploited?
Listed in the CISA KEV catalog on 2026-06-23.
Federal remediation due 2026-06-26.
Past that date by 50 days.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-67038
PlainSec has not published a story about this CVE.