Knox CVE Database
/
CVE-2025-67038
Critical
9.8

CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Added to the CISA KEV catalog:
June 23, 2026

Overview

The Lantronix EDS5000 series (EDS5008, EDS5016, and EDS5032) running firmware version 2.1.0.0R3 contains an OS command injection flaw in its HTTP RPC module. When a login attempt fails, the device constructs a shell command to log the event by concatenating the supplied username directly into the command string without any sanitization. An unauthenticated remote attacker who can reach the HTTP interface can supply a crafted username containing shell metacharacters, causing the device to execute arbitrary commands with root privileges and achieving full device compromise.

Vulnerability details

Affected vendor
Lantronix
Affected product
EDS5000
Weakness type (CWE)
CWE-78, CWE-94

The flaw is a classic OS command injection (CWE-78): user-supplied input is concatenated directly into a shell command string without escaping or validation. In this product, the HTTP RPC module triggers a logging shell command on every failed authentication attempt. Because the username field is passed verbatim into that command, any shell metacharacter or subcommand sequence embedded in the username is interpreted by the shell rather than treated as data. The device runs the resulting command as root, meaning no privilege boundary exists between the injected payload and full system control.


An attacker sends a crafted HTTP authentication request to the EDS5000's HTTP RPC interface with a malicious username field containing OS command injection payloads. No prior authentication or user interaction is required: the vulnerable code path executes during the failure-handling routine, before any credential is validated. Successful exploitation yields arbitrary command execution with root privileges, giving the attacker complete control over the device, including access to all data it handles, the ability to modify its configuration or firmware, and the ability to disrupt its serial-to-network bridging functions.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor HTTP server logs on the EDS5000 for authentication failure events where the username field contains shell metacharacters such as semicolons, backticks, pipe symbols, dollar signs followed by parentheses, or newline sequences, which are not present in legitimate login attempts.
  • Audit network traffic to the EDS5000's HTTP management port for repeated unauthenticated requests with unusually long or syntactically abnormal username values, particularly from sources outside the expected management network segment.
  • Review device syslog output for unexpected process execution or log entries that do not match the standard authentication-failure format, which may indicate injected commands were appended to the logging shell invocation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 26, 2026

Additional hardening

  • Apply the latest firmware for the EDS5008, EDS5016, and EDS5032 available from Lantronix (see References); firmware 2.1.0.0R3 is the confirmed affected version and should be replaced as the primary remediation.
  • Restrict network access to the EDS5000 HTTP management interface using firewall rules or ACLs so that only trusted management hosts or networks can reach the HTTP port, reducing the attack surface for unauthenticated exploitation.
  • Place EDS5000 devices on an isolated management VLAN or out-of-band management network, preventing general-purpose or internet-facing hosts from reaching the HTTP RPC interface entirely.
  • If patching or network isolation cannot be applied immediately, consider disabling the HTTP management interface where the device's operational requirements permit, or monitor it continuously for anomalous authentication activity as a compensating control.

Key dates

Published (NVD)
March 11, 2026
Added to CISA KEV
June 23, 2026
Remediation deadline
June 26, 2026
Last updated
July 6, 2026

References

Frequently asked questions

Does CVE-2025-67038 affect my FedRAMP authorization?

If Lantronix EDS5000 operates inside your authorization boundary, CVE-2025-67038 affects your FedRAMP authorization directly. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of June 26, 2026. An unpatched KEV inside your boundary is an assessor finding. Before that deadline, you must either remediate it or formally document a mitigation, or your sponsoring agency will raise it.

How does Knox help me handle CVE-2025-67038?

Knox does not patch Lantronix EDS5000 on your behalf. Under the FedRAMP shared-responsibility model, that remediation is yours to own. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that work, along with Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The patch is your responsibility; maintaining a compliant posture while you apply it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2025-67038. When exposure exists, it surfaces during ongoing monitoring rather than waiting to be flagged at an assessor review, giving you time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2025-67038 isn't remediated by June 26, 2026?

Missing the June 26, 2026 deadline turns CVE-2025-67038 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization standing clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting