Security
Loading…

CVE-2025-67038

CRITICALCVSS 9.8Known Exploited
Description

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Timeline
Published:March 11th, 2026 5:16 PM
Last modified:September 8th, 2026 7:00 PM
Added to KEV:June 23rd, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

lantronix

Products

eds5008_firmwareeds5016_firmwareeds5032_firmwareg526gp12s_firmwareg526gp17s_firmwareg526gp1cs_firmwareg526gp1asg_firmwareg526gp1as_firmwareg527gp22s_firmwareg527gp27s_firmwareg527gp2as_firmwareg527gp2asg_firmwareg528gp2fs_firmwareg528gp2fsg_firmwareg528gp2fsgc_firmwarex300f202s_firmwarex303f202s_firmwarex304g00as_firmwarex304g000s_firmwarex304g002s_firmware
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute