Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2025-67038: Lantronix EDS5000 allows remote code execution through username field

Known exploited
CVE-2025-67038 CVE-2025-67038 CVE-2025-67038
Summary

Lantronix's EDS5000 2.1.0.0R3 has a security flaw that allows hackers to execute commands on the device by manipulating the username field when authentication fails. This means an attacker could potentially take control of the device. To protect your device, apply the latest updates and ensure you're running the latest software version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
lantronix eds5000 All versions
lantronix eds5032_firmware 2.1.0.0r3
cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:*
lantronix eds5008_firmware 2.1.0.0r3
cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:*
lantronix eds5016_firmware 2.1.0.0r3
cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:*
Original title
Lantronix EDS5000 Code Injection Vulnerability
Original description
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Vulnerability type
CWE-94 Code Injection
Published: 23 Jun 2026 · Updated: 23 Jul 2026 · First seen: 11 Mar 2026