CVE-2025-67038

Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability

Situation assessment

A code injection vulnerability in Lantronix EDS5000 allows attackers to inject arbitrary OS commands into the username parameter, which are executed with root privileges. This affects multiple firmware versions, including 2.2.0.0r1 and 2.6.0.4R6. The vulnerability is actively exploited, particularly in ransomware campaigns, necessitating an immediate upgrade to version 2.2.0.0r1. It is listed in the CISA KEV catalog, highlighting its critical nature.

Affected

  • lantronix/eds5008_firmware lt *..2.2.0.0r1
  • lantronix/eds5016_firmware lt *..2.2.0.0r1
  • lantronix/eds5032_firmware lt *..2.2.0.0r1
  • lantronix/g526gp12s_firmware lt *..2.6.0.4R6
  • lantronix/g526gp17s_firmware lt *..2.6.0.4R6
  • lantronix/g526gp1cs_firmware lt *..2.6.0.4R6
  • lantronix/g526gp1asg_firmware lt *..2.6.0.4R6
  • lantronix/g526gp1as_firmware lt *..2.6.0.4R6
  • lantronix/g527gp22s_firmware lt *..2.6.0.4R6
  • lantronix/g527gp27s_firmware lt *..2.6.0.4R6
  • lantronix/g527gp2as_firmware lt *..2.6.0.4R6
  • lantronix/g527gp2asg_firmware lt *..2.6.0.4R6
  • lantronix/g528gp2fs_firmware lt *..2.6.0.4R6
  • lantronix/g528gp2fsg_firmware lt *..2.6.0.4R6
  • lantronix/g528gp2fsgc_firmware lt *..2.6.0.4R6
  • lantronix/x300f202s_firmware lt *..2.6.0.4R6
  • lantronix/x303f202s_firmware lt *..2.6.0.4R6
  • lantronix/x304g00as_firmware lt *..2.6.0.4R6
  • lantronix/x304g000s_firmware lt *..2.6.0.4R6
  • lantronix/x304g002s_firmware lt *..2.6.0.4R6
  • lantronix/x304g007s_firmware lt *..2.6.0.4R6
  • lantronix/x304g00cs_firmware lt *..2.6.0.4R6
  • lantronix/e228g002s_firmware lt *..3.21.0.0R1
  • lantronix/e228g004s_firmware lt *..3.21.0.0R1
  • lantronix/e228g00cb28_firmware lt *..3.21.0.0R1
  • lantronix/e228g00cs_firmware lt *..3.21.0.0R1
  • lantronix/e213f102s_firmware lt *..3.21.0.0R1
  • lantronix/e214f002s_firmware lt *..3.21.0.0R1
  • lantronix/e214f00cs_firmware lt *..3.21.0.0R1
  • lantronix/e214g000s_firmware lt *..3.21.0.0R1
  • lantronix/e214g001s_firmware lt *..3.21.0.0R1
  • lantronix/e218f004s_firmware lt *..3.21.0.0R1
  • lantronix/e218g107s_firmware lt *..3.21.0.0R1

Response & Mitigation

Why act now?

Prioritisation rationale

CVE-2025-67038 scores CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning it is exploitable over the network with no authentication, no user interaction, and low complexity — the highest possible risk profile for a network-facing device. The EPSS score of 15.67 % at the 96.6th percentile places this well above the threshold for imminent exploitation activity. EDS5000 devices are serial device servers commonly deployed in industrial control, data centre, and critical infrastructure environments; root-level code execution enables full device takeover, lateral movement into OT networks, and potential disruption of attached serial equipment. NIS2-scoped organisations operating OT or industrial networks should treat this as a critical finding and target patch deployment or network isolation within 24 hours.

Runbook · Step 1

Immediate response (0-24 h)

  • Identify all Lantronix EDS5000 devices (EDS5008, EDS5016, EDS5032) in your environment immediately — compare asset inventory against firmware version 2.1.0.0R3 and check the vendor advisory for a patched release (lantronix.com/support; do not assume a specific version number without confirming with the vendor).
  • Block HTTP access (ports 80/443) to the EDS5000 RPC module at the network perimeter immediately — restrict access to dedicated management hosts only via firewall ACL.
  • Isolate any device that cannot be patched immediately by moving it to a dedicated management VLAN with strict ingress/egress ACLs.
  • Review all authentication logs on affected devices for username fields containing shell metacharacters (;, |, $(), backtick, newline) — these are direct indicators of exploitation attempts.
  • Rotate all credentials configured on EDS5000 devices; assume root-level compromise on any device that was reachable from untrusted networks prior to isolation.

Runbook · Step 2

Mitigation layers

  • Network segmentation: Place all EDS5000 devices exclusively in a dedicated OT/IoT management VLAN; block inbound HTTP/HTTPS from the general corporate network via ACL.
  • WAF/IPS rule: Filter HTTP POST requests to the login endpoint — block payloads containing shell metacharacters (;, |, &&, $(, backtick, \n) in the username parameter. Example Snort/Suricata rule: alert http any any -> $EDS_HOSTS any (msg:"CVE-2025-67038 OS Injection attempt"; http.request_body; content:"username="; pcre:"/username=[^&]*[;| + "" + $\n]/i"; sid:2025670380; rev:1;)`.
  • Least privilege / access control: Enforce MFA-protected jump-host access for all device management; remove any direct internet-facing exposure immediately.
  • Configuration hardening: Where firmware permits, disable plain HTTP and enforce HTTPS only; disable unused RPC endpoints to reduce attack surface.
  • Compensating monitoring: Enable syslog forwarding from all EDS5000 devices to a central log collector if not already active — this preserves authentication event visibility even if a device is compromised.

Runbook · Step 3

Detection rules

  • Web/proxy access logs: HTTP POST requests to the EDS5000 login endpoint with username values containing shell metacharacters — SPL example: index=proxy uri="*/login*" form_data="*username=*" (form_data="*;*" OR form_data="*|*" OR form_data="*$(*" OR form_data="* + "" + *")`.
  • Network telemetry (Zeek/Suricata): Outbound connections originating from EDS5000 IP addresses to unknown external hosts following a failed authentication event — indicative of a successful reverse shell via command injection.
  • Device syslog: Repeated authentication failures with unusually long or metacharacter-containing usernames — Sigma rule shape: keywords: ['authentication failure', 'username'] | filter: username|re: '[;| + "" + $&\n]'`.
  • EDR (management jump-host): Unexpected outbound connections from the jump-host or lateral movement to OT network segments following an EDS5000 management session.
  • Integrity monitoring: Periodically compare EDS5000 configuration files and firmware hashes against a known-good baseline — unauthorised changes post-authentication are a strong indicator of root-level compromise.

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Affected operating systems

  • other

    lantronix / e213f102s_firmware

  • other

    lantronix / e214f002s_firmware

  • other

    lantronix / e214f00cs_firmware

  • other

    lantronix / e214g000s_firmware

  • other

    lantronix / e214g001s_firmware

  • other

    lantronix / e218f004s_firmware

  • other

    lantronix / e218g107s_firmware

  • other

    lantronix / e228g002s_firmware

  • other

    lantronix / e228g004s_firmware

  • other

    lantronix / e228g00cb28_firmware

  • other

    lantronix / e228g00cs_firmware

  • other

    lantronix / eds5008_firmware2.1.0.0

  • other

    lantronix / eds5008_firmware2.1.0.0r3

  • other

    lantronix / eds5008_firmware

  • other

    lantronix / eds5016_firmware2.1.0.0

  • other

    lantronix / eds5016_firmware2.1.0.0r3

  • other

    lantronix / eds5016_firmware

  • other

    lantronix / eds5032_firmware2.1.0.0

  • other

    lantronix / eds5032_firmware2.1.0.0r3

  • other

    lantronix / eds5032_firmware

  • other

    lantronix / g526gp12s_firmware

  • other

    lantronix / g526gp17s_firmware

  • other

    lantronix / g526gp1as_firmware

  • other

    lantronix / g526gp1asg_firmware

Metrics

9.8
Source: nvd-v3
97.4 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Actively exploited
Show all metrics
Severity
critical
actively exploited (KEV)
20.0 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2026-03-11 17:16 UTC
CWE-78

Weakness classes (CWE)

  • CWE-78Base

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

    cwe.mitre.org →

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Reanalysis2026-09-08 19:00 UTC· nvd@nist.gov
    • CPE Configuration: AND OR *cpe:2.3:o:lantronix:g527gp22s_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:lantronix:g527gp22s:-:*:*:*:*:*:*:* → AND OR *cpe:2.3:o:lantronix:g527gp22s_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.0.4R6 OR cpe:2.3:h:lantronix:g527gp22s:-:*:*:*:*:*:*:*
  2. Modified Analysis2026-09-08 18:56 UTC· nvd@nist.gov
    • CPE Configuration: AND OR *cpe:2.3:o:lantronix:eds5032_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.2.0.0r1 OR cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:lantronix:g526gp12s_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.0.4R6 OR cpe:2.3:h:lantronix:g526gp12s:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:lantronix:g526gp17s_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.0.4R6 OR cpe:2.3:h:lantronix:g526gp17s:-:*:*:*:*:*:*:*
    • CPE Configuration: AND OR *cpe:2.3:o:lantronix:g526gp1cs_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 2.6.0.4R6 OR cpe:2.3:h:lantronix:g526gp1cs:-:*:*:*:*:*:*:*
  3. CVE Modified2026-09-08 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2025-67038","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic… → {"id":"CVE-2025-67038","role":"CISA Coordinator","options":[{"exploitation":"active"},{"automatable":"yes"},{"technic…
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-94
  4. CVE Modified2026-09-04 21:17 UTC· ics-cert@hq.dhs.gov
    • Description: An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. → An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
    • CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-78
  5. CVE Modified2026-09-04 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
    • Reference: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
    • Reference Type: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038 Types: US Government Resource

Linked advisories