Status: KEV
| Advisory ID: CVE-2025-67038
Key Details
| CVE | CVE-2025-67038 |
| Vulnerability Name | Lantronix EDS5000 Code Injection Vulnerability |
| Affected products | Lantronix EDS5000 |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-06-23. |
| Exploitation prediction (EPSS) | 19.26% probability of exploitation in the next 30 days (97% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-06-26 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
What to Do
Monitor Lantronix's web page for any future patch releases.
References
KEV Required Action