LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 23, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog on Jun 23, 2026, with a federal patch deadline of Jun 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

This vulnerability affects the Lantronix EDS5000 and permits injection of arbitrary operating system commands via the username parameter. Commands execute with root privileges, which can result in full control of the device.

IT and security teams should prioritize identification and mitigation because the weakness provides an attacker with privileged access on an exposed system.

How it works

The issue is tracked under CWE-78 and CWE-94. These describe failures to neutralize special elements in operating system commands and improper control of code generation.

An attacker supplies crafted input in the username parameter. The device then executes the supplied commands on the underlying operating system with root privileges.

Am I affected? How to find it in your systems

Locate every Lantronix EDS5000 instance through asset inventories, network scans, or configuration management databases. Confirm the exact versions and settings against the vendor advisory.

Review authentication and input-handling logs for anomalous entries that could indicate attempted or successful command injection. Specific telemetry indicators must be validated against vendor guidance.

How to remediate

Apply mitigations exactly as stated in the vendor instructions. This is the required first action.

If you can't patch immediately

Apply BOD 26-04 guidance for cloud services or discontinue use of the product when mitigations cannot be implemented.

If your data may have been exposed

Actively exploited vulnerabilities can result in breaches. Run a free exposure scan of your email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLantronix · EDS5000
WeaknessCWE-78
Added to CISA KEVJun 23, 2026
Federal patch deadlineJun 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities