CVE-2025-67038 is a critical OS command injection vulnerability affecting Lantronix EDS5000 series devices (EDS5008, EDS5016, EDS5032) running firmware 2.1.0.0R3. The flaw allows unauthenticated attackers to inject arbitrary OS commands into the username parameter during failed HTTP RPC authentication attempts, which are then executed with root privileges due to a lack of sanitization in the logging mechanism. Rated 9.8 Critical (CVSSv3.1), this vulnerability has a low attack complexity and can lead to a complete compromise of the affected device's confidentiality, integrity, and availability. There is currently no evidence of active exploitation, nor public exploit code available, though it has received minimal community attention, including a mention in CISA alerts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:* | ||
2.1.0.0r3CPE matchmatch criteria | cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.