Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2025-67038: Lantronix EDS5000 allows remote code execution through username field
Known exploited
CVE-2025-67038
CVE-2025-67038
CVE-2025-67038
Summary
Lantronix's EDS5000 2.1.0.0R3 has a security flaw that allows hackers to execute commands on the device by manipulating the username field when authentication fails. This means an attacker could potentially take control of the device. To protect your device, apply the latest updates and ensure you're running the latest software version.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lantronix | eds5000 | All versions |
| lantronix | eds5032_firmware |
2.1.0.0r3 cpe:2.3:o:lantronix:eds5032_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
| lantronix | eds5008_firmware |
2.1.0.0r3 cpe:2.3:o:lantronix:eds5008_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
| lantronix | eds5016_firmware |
2.1.0.0r3 cpe:2.3:o:lantronix:eds5016_firmware:2.1.0.0r3:*:*:*:*:*:*:* |
Original title
Lantronix EDS5000 Code Injection Vulnerability
Original description
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Vulnerability type
CWE-94
Code Injection
Published: 23 Jun 2026 · Updated: 23 Jul 2026 · First seen: 11 Mar 2026