cbcvebase.
CVE-2025-67038
published 2026-03-11

CVE-2025-67038: An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The…

PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-06-26
Exploited in the wild
EPSS
21.98%
97.5th percentile
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
lantronixe210_series< 3.21.0.0R13.21.0.0R1
lantronixe213f102s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe214f002s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe214f00cs_firmware< 3.21.0.0R13.21.0.0R1
lantronixe214g000s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe214g001s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe218f004s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe218g107s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe220_series< 3.21.0.0R13.21.0.0R1
lantronixe228g002s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe228g004s_firmware< 3.21.0.0R13.21.0.0R1
lantronixe228g00cb28_firmware< 3.21.0.0R13.21.0.0R1
lantronixe228g00cs_firmware< 3.21.0.0R13.21.0.0R1
lantronixeds5000_series<= 2.1.0.0R3
lantronixeds5008_firmware< 2.2.0.0r12.2.0.0r1
lantronixeds5016_firmware< 2.2.0.0r12.2.0.0r1
lantronixeds5032_firmware< 2.2.0.0r12.2.0.0r1
lantronixg520_series< 2.6.0.4R62.6.0.4R6
lantronixg526gp12s_firmware< 2.6.0.4R62.6.0.4R6
lantronixg526gp17s_firmware< 2.6.0.4R62.6.0.4R6
lantronixg526gp1as_firmware< 2.6.0.4R62.6.0.4R6
lantronixg526gp1asg_firmware< 2.6.0.4R62.6.0.4R6
lantronixg526gp1cs_firmware< 2.6.0.4R62.6.0.4R6
lantronixg527gp22s_firmware< 2.6.0.4R62.6.0.4R6
lantronixg527gp27s_firmware< 2.6.0.4R62.6.0.4R6

Detection & IOCsextracted from sources · hover to see the quote

  • Inject arbitrary OS commands via the username parameter in the HTTP RPC module login request; monitor for shell metacharacters or command sequences in authentication username fields on Lantronix EDS5000 devices
  • Target device and firmware version for detection scoping: Lantronix EDS5000 running firmware 2.1.0.0R3; the vulnerable code path is the HTTP RPC module's failed-authentication log-writing shell command
  • Alert on failed authentication attempts to Lantronix EDS5000 HTTP RPC endpoints where the username field contains shell special characters (e.g., ;, |, $(), backticks), as the username is concatenated directly into a shell command
  • CVE-2025-67038 is part of the BRIDGE:BREAK vulnerability set disclosed by Forescout Research Vedere Labs targeting serial-to-IP converters; correlate with other BRIDGE:BREAK indicators when triaging
  • ·Vulnerable firmware version is 2.1.0.0R3; patched version is 2.2.0.0R1. Ensure detection rules are scoped to unpatched EDS5000 devices and suppressed after upgrade.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.