ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2025-67038

CRITICAL Export PDF

Lantronix EDS5000 Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

CVSS Score
9.8
CRITICAL
Published
23 Jun 2026 00:00
Modified
N/A
Vendor
Lantronix
Product
EDS5000
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-78 CWE-94

Affected Systems

Lantronix
EDS5000
Lantronix
EDS5000

KEV Status

Known Exploited Vulnerability