CVE-2025-67038 – Critical Remote Code Execution in Lantronix EDS5000 Series
Key takeaways
- Critical RCE via unauthenticated HTTP RPC command injection (CWE‑94).
- Affects Lantronix EDS3000PS and EDS5000 devices (firmware 2.1.0.0R3).
- Active exploitation observed in the wild; added to CISA KEV.
- Patch released Feb 20 2026; U.S. federal agencies must remediate by 2026‑06‑26.
Overview
Lantronix devices are widely deployed as serial‑to‑IP converters in industrial control environments. CVE-2025-67038 is a command‑injection flaw in the HTTP RPC module that allows an unauthenticated attacker to execute arbitrary OS commands with root privileges. The vulnerability stems from an unsanitized username parameter that is concatenated into a shell command during failed‑authentication logging.
Technical Details
- Vulnerability type: CWE‑94 (Improper Neutralization of Special Elements used in an OS Command – “Command Injection”).
- Affected firmware: 2.1.0.0R3 (and earlier) on EDS3000PS / EDS5000.
- Attack vector: Network‑reachable HTTP RPC endpoint (default port 80/443).
- Exploit flow:
- Send an HTTP request that triggers a failed‑authentication log.
- Inject a malicious string in the username field (e.g.,
; id;). - The device logs the string without sanitization, executing it as a shell command.
- The command runs with root privileges, granting full system control.
CVSS 3.1: 9.8 (Critical) – AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity & Impact
The flaw enables remote code execution without authentication, giving attackers full root access to the device. In an OT context, compromise can lead to:
- Disruption of industrial processes.
- Lateral movement to other OT/IT assets.
- Data exfiltration or sabotage of control logic.
Given the Critical CVSS score and the fact that the vulnerability is actively exploited, immediate action is required.
Affected Products
- Lantronix EDS3000PS (serial‑to‑IP converter)
- Lantronix EDS5000 series (including firmware 2.1.0.0R3)
For a complete list of affected versions and CPE identifiers, see the official CVE page:
https://vulnsocial.com/cve/CVE-2025-67038
What You Should Do Now
- Inventory – Identify all Lantronix EDS3000PS/EDS5000 devices on your network.
- Check firmware – Verify the running firmware version; any version ≤ 2.1.0.0R3 is vulnerable.
- Apply the vendor patch – Lantronix released a fix on Feb 20 2026 (see vendor advisory).
- Network‑level controls – If patching cannot be performed immediately:
- Block inbound traffic to the HTTP RPC port from untrusted networks.
- Enforce strict firewall rules or place devices in a segmented VLAN.
- Detect abuse – Deploy IDS/IPS signatures that look for suspicious
username=parameters in HTTP requests to the RPC endpoint. - CISA compliance – Federal civilian agencies must complete remediation by 2026‑06‑26 per the CISA KEV deadline.
Remediation & Mitigation Steps
| Step | Action |
|---|---|
| 1 | Patch the device firmware to the latest Lantronix release (≥ 2.1.0.0R4). |
| 2 | If patching is delayed, disable the HTTP RPC service or restrict it to management VLANs. |
| 3 | Implement network segmentation between OT and IT zones. |
| 4 | Add IPS/IDS rule to alert on username= parameters containing shell metacharacters (;, &&, ` |
| 5 | Conduct post‑remediation validation – attempt a benign request to confirm the injection vector is blocked. |
| 6 | Update asset management databases to flag the device as “patched” or “mitigated”. |
Bottom Line
CVE-2025-67038 is a Critical remote code execution flaw in Lantronix EDS3000PS/EDS5000 devices that is actively exploited and listed in the CISA KEV catalog. Apply the vendor patch immediately, enforce network controls, and monitor for malicious RPC traffic.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-67038
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02
- https://vulnsocial.com/cve/CVE-2025-67038
#CVE #CVE202567038 #Critical #RCE #CISAKEV #Lantronix #EDS5000
