CVE-2025-67038Active Exploitation(lantronix / e213f102s)

HIGHCVSS 9.3 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch lantronix e213f102s systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-26. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • e213f102s
  • e213f102s_firmware
  • e214f002s
  • e214f002s_firmware

Threat summary

  • Active exploitation appears in 31 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 37 mentions across 14 observed days

What's happening

  • Active exploitation reported across 31 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 24 signals
  • Disclosure: 5 classified signals
  • Peaked 11d ago at 9 mentions (2026-06-24); latest day: 1
  • 37 total mentions across 14 days

Affected systems

Vendors
Products
e213f102se213f102s_firmwaree214f002se214f002s_firmwaree214f00cse214f00cs_firmwaree214g000se214g000s_firmwaree214g001se214g001s_firmware

1 version affected across 66 products

Deep dive

Activity timeline37 mentions / 14d
02579Mentions · 2026-03-15: 1Mentions · 2026-06-23: 2Mentions · 2026-06-24: 9Mentions · 2026-06-25: 7Mentions · 2026-06-26: 7Mentions · 2026-06-28: 2Mentions · 2026-06-29: 2Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-05: 1Mentions · 2026-07-21: 1Mentions · 2026-08-28: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-06-24: 1PoC Mentioned / Linked · 2026-06-26: 1Active Exploitation · 2026-06-23: 2Active Exploitation · 2026-06-24: 6Active Exploitation · 2026-06-25: 7Active Exploitation · 2026-06-26: 7Active Exploitation · 2026-06-28: 1Active Exploitation · 2026-06-29: 2Active Exploitation · 2026-06-30: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 3Patch / Workaround · 2026-06-25: 3Patch / Workaround · 2026-06-26: 2Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-03-15: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 7Technical Details · 2026-06-25: 5Technical Details · 2026-06-26: 4Technical Details · 2026-06-28: 1Technical Details · 2026-06-29: 2Technical Details · 2026-07-02: 1Technical Details · 2026-07-21: 1Technical Details · 2026-08-28: 103-1506-2306-2406-2506-2606-2806-2906-3007-0107-0207-0507-2108-2810-06
Signal classification3 categories
Active Exploitation
2980.6%
Disclosure
513.9%
Patch
25.6%
Referenced assets66 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-151
Disclosure1
2026-06-232
Disclosure1Patch1
2026-06-249
Active Exploitation6Disclosure3
2026-06-257
Active Exploitation7
2026-06-267
Active Exploitation7
2026-06-282
Active Exploitation1Patch1
2026-06-292
Active Exploitation2
2026-06-301
Active Exploitation1
2026-07-011
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-051
Active Exploitation1
2026-07-211
Active Exploitation1
2026-08-281
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    A critical Lantronix flaw is now under active exploitation. CISA says CVE-2025-67038 affects EDS5000 Series devices and can let attackers run commands with root privileges. Federal civilian agencies have until June 26, 2026, to patch. Learn more: https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html https://t.co/jCg680nS1f

    Post summary

    The Lantronix CVE-2025-67038 is now being actively exploited, allowing root‑level command execution on EDS5000 devices, with a mandatory patch deadline for U.S. federal civilian agencies.

    326468629.8K
    2.2M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ UPDATE - Forescout says CVE-2025-67038 was exploited as a zero-day. The Lantronix flaw was used against honeypots as early as April 5, weeks before BRIDGE:BREAK was publicly disclosed. Attackers may have reverse-engineered the Feb. 20 patch to build the exploit. Read: https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html

    Post summary

    CVE-2025-67038 has been actively exploited as a zero‑day, with attackers targeting honeypots and likely reverse‑engineering the Feb. 20 patch to build their exploit. No PoC, exploit code, patch, or detailed technical vulnerability information is included in the text.

    316265753.4K
    2.2M followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2025-67038: Lantronix EDS5000 HTTP RPC module Command Execution Critical Vulnerability Alert! Lantronix is affected by CVE-2025-67038. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2025-67038 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2025-67038" Search Dork: app="Lantronix" Exposure: 54.5k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJMYW50cm9uaXgi&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260624 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    A critical command‑execution vulnerability (CVE‑2025‑67038) affecting Lantronix EDS5000 devices has been disclosed, with detailed analysis available via DarkEye, but no PoC, exploit, or active exploitation evidence is reported.

    0802263.2K
    12.6K followersView on X
  • kmkz@kmkz_security
    Active Exploitation

    #Lantronix - CVE-2025-67038 Failed auth: HTTP RPC module shells out to write a log & concatenates the username into that command, unsanitized (I know🙃)-> root, 1 request⚠️ Tampered serial data in transit so the gateway hides a dangerous condition: no info > Now in CISA #KEV

    Post summary

    CVE-2025-67038 allows attackers to execute arbitrary commands through an unsanitized username in HTTP RPC, potentially gaining root, and is now listed in CISA's KEV indicating active exploitation in the wild.

    210953.0K
    19.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(6/23追加) 🛡CVE-2025-67038 ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Lantronix EDS5000 2.1.0.0R3 の HTTP RPC モジュールに存在する脆弱性です。 認証失敗時のログ書き込み処理で username パラメータがサニタイズされずにシェルコマンドへ連結されます。 悪用により、攻撃者が任意の OS コマンドを root 権限で実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・Lantronix EDS5000 2.1.0.0R3 を使用している ・HTTP RPC インターフェースへ攻撃者がネットワーク経由でアクセスできる ・認証失敗時のログ書き込み処理が影響を受ける状態である ・修正済みファームウェアまたは緩和策が適用されていない ✅悪用時影響 ・username パラメータ経由で任意の OS コマンドを挿入される可能性がある ・挿入されたコマンドを root 権限で実行される可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ・ネットワーク機器を踏み台化される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2025-67038 ・http://lantronix.com ・https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02 ・https://github.com/cisagov/vulnrichment/blob/develop/2025/67xxx/CVE-2025-67038.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038 🛡CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切なアクセス制御 (CWE-284) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切なアクセス制御の脆弱性です。 ネットワークアクセス可能な攻撃者が、本来許可されないシステム変更を実行できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・不正なシステム変更を実行される可能性がある ・認証を回避して内部機能へ到達される可能性がある ・他の UniFi OS 脆弱性と組み合わせてリモートコード実行につながる可能性がある ・機器の機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34908 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34908.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34908 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在するパス・トラバーサルの脆弱性です。 ネットワークアクセス可能な攻撃者が、基盤システム上のファイルへアクセスし、基盤アカウントへのアクセスに悪用できる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・修正済みバージョンへ更新されていない ✅悪用時影響 ・基盤システム上のファイルへアクセスされる可能性がある ・ファイルアクセスを悪用して基盤アカウントへのアクセスにつなげられる可能性がある ・他の UniFi OS 脆弱性と組み合わせて機器を侵害される可能性がある ・機密性、完全性、可用性に高い影響が生じる ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34909 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34909.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34909 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ 🛡CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability ✅概要 ・深刻度:緊急 10.0 (CVSS Base) / HackerOne (CNA) ・種別:不適切な入力確認 (CWE-20) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H UniFi OS デバイスに存在する不適切な入力確認の脆弱性です。 ネットワークアクセス可能な攻撃者が細工した入力を送信することで、コマンドインジェクションを実行できる可能性があります。 悪用により、対象機器上で任意の OS コマンド実行につながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・SSVC 悪用の状況:悪用確認済 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 (GitHub) ✅攻撃前提条件 ・影響を受ける UniFi OS デバイスまたは UniFi OS Server を使用している ・攻撃者が対象機器へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・入力検証不備を含む更新処理または関連機能が影響を受ける状態である ・修正済みバージョンへ更新されていない ✅悪用時影響 ・コマンドインジェクションを実行される可能性がある ・対象機器上で任意の OS コマンドを実行される可能性がある ・Mirai 系ボットのローダーやインプラントを配置される可能性がある ・機器の完全な侵害につながる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(PwnDefend / Xservus Limited) PwnDefend は Defused honeypot とトリアージにより、UniFi OS の SAB-064 関連脆弱性を悪用した Mirai 系ボット化の実悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34910 ・https://community.ui.com/releases/Security-Advisory-Bulletin-064-064/84811c09-4cf4-42ab-bd61-cc994445963b ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34910.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34910 ・https://www.pwndefend.com/2026/06/09/cve-2026-34910-exploitation-itw-building-a-botnet-mirai/ https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post lists several CVEs added to CISA’s Known Exploited Vulnerabilities catalog, provides comprehensive technical details, and confirms that active exploitation has been observed for the Ubiquiti UniFi OS vulnerabilities.

    010626.7K
    44.1K followersView on X
  • ShiftSix Security@Shift6Security
    Active Exploitation

    Root shell via the username field. No credentials needed. CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters. Exploited in the wild before Forescout published the technical details. CISA KEV since June 23.

    Post summary

    CVE‑2025‑67038 in Lantronix EDS5000 serial‑to‑IP converters is actively exploited, providing a root shell through the username field with no credentials, and has been flagged by CISA as a KEV.

    01010111
    1.8K followersView on X
  • INFOSEC.WATCH@InfosecDotWatch
    Active Exploitation

    CISA added three Ubiquiti UniFi OS flaws and Lantronix EDS5000 CVE-2025-67038 to KEV. Patch or isolate management paths and inspect for unauthorized changes. https://www.cisa.gov/news-events/alerts/2026/06/23/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added three Ubiquiti UniFi OS flaws and Lantronix EDS5000 CVE-2025-67038 to its Known Exploited Vulnerabilities catalog, urging organizations to patch or isolate management paths and monitor for unauthorized changes.

    1001063
    36 followersView on X
  • Nullvy | CyberNews@NullvyNews
    Active Exploitation

    حذرت وكالة الأمن السيبراني الأمريكية من استغلال نشط للثغرة CVE-2025-67038 في أجهزة لانترونيكس EDS5000، ودعت إلى تطبيق التحديثات الأمنية بشكل عاجل. 📌 للتفاصيل الكاملة: 🔗 https://www.instagram.com/p/DaAEFO2oRky/?igsh=cHY5bDB5dnBhdnM= #cisa #vulnerabilities https://t.co/8LBCwRLpqg

    Post summary

    CISA reports that CVE-2025-67038 is being actively exploited on Lantronics EDS5000 devices and urges immediate patching.

    0002077
    25 followersView on X
  • GoCocoaAI@GoCocoaAI
    Disclosure

    A command injection flaw in Lantronix EDS5000 serial-to-Ethernet device servers hit CISA's KEV catalog yesterday. CVE-2025-67038, CVSS 9.8. Federal civilian agencies have until June 26 to patch. That's 48 hours. The mechanics are as clean as they get. The HTTP RPC module constructs a shell command to log failed authentication attempts — and concatenates the supplied username directly into that command, unsanitized. Send a crafted username with OS command metacharacters. The shell executes them as root. The trigger is a failed login, meaning exploitation requires no valid credentials whatsoever, just network reachability to the HTTP RPC port. Pre-auth. Root. No complexity. Three for three on the criteria that make a CVE immediately weaponizable. Affected firmware is 2.1.0.0R3 across the EDS5008, EDS5016, and EDS5032. The vulnerability class is CWE-78 OS command injection. CVSS vector: AV:N/AC:L/PR:N/UI:N — as permissive as the scoring system allows. The device class matters here. EDS5000 units are serial device servers — they sit at the boundary between legacy serial-connected OT equipment (PLCs, RTUs, SCADA terminal servers) and IP-routed networks. A root shell on one of these is not just a box compromise. It's a potential pivot into the OT network behind it, with the ability to relay or interfere with serial communications to industrial equipment. Serial device servers have a well-earned reputation for sitting in network closets and on plant floors, quietly forgotten, unpatched for years. They are nothing if not consistent. CISA added CVE-2025-67038 on June 23 alongside three Ubiquiti UniFi OS CVEs — CVE-2026-34908 at CVSS 10.0, CVE-2026-34909, and CVE-2026-34910 — all carrying the same June 26 deadline. A four-CVE batch, two vendors, one date, coordinated federal urgency. The pattern suggests a wave, not isolated incidents. MITRE mapping: T1190 (Exploit Public-Facing Application) for initial access, T1059.004 (Unix Shell) for execution, T1068 for privilege escalation, and T1059.008 as the likely OT pivot path. Known ransomware use is currently unconfirmed, but the device class and pivot potential make this an attractive staging point. For federal agencies, June 26 is the clock. For everyone else, that deadline is yours too. Lantronix patch firmware is available. CISA ICS Advisory ICSA-26-069-02 has the full technical breakdown. If UniFi infrastructure is in scope, the CVSS 10.0 co-listed CVE warrants its own look.

    Post summary

    The post announces CVE-2025-67038, a high‑severity command injection in Lantronix EDS5000 devices, details its mechanics and patch deadline, and confirms that a firmware patch is available.

    10010170
    34 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-67038, an unauthenticated OS command injection in Lantronix EDS5000 serial-to-IP converters, was exploited in the wild before public disclosure, suggesting patch-diff reverse engineering by a targeted threat cluster. Key findings: - CVE-2025-67038 lives in OpenWRT LuCI's HTTP JSON-RPC auth endpoint. The username field in /cgi-bin/luci/rpc/auth is concatenated unsanitized into a log string passed to os.execute, allowing root command execution with no credentials. Exploitation probes injected sleep tests then capability-check callbacks to C2s at 154.219.113[.]56 and 38.180.201[.]49, with filenames like lntxe1-lntxea confirming the actor knew exactly what device they were hitting. - The cluster, named Chaya_006, operated April 5 to June 3 from scanner IPs across Asia (Japan 🇯🇵, Taiwan 🇹🇼, South Korea 🇰🇷, China 🇨🇳). Scanner IPs include 38.207.136[.]2 and 59.124.166[.]52. The actor rotated user-agents from curl to Chrome to Firefox to blend in, a deliberate evasion step, not scanner noise. - Parallel to Chaya_006, over 4,100 brute-force attempts hit OpenWRT LuCI /cgi-bin/luci/ endpoints between January and June, cycling hundreds of password combinations across four usernames. Nearly 32,000 LuCI-exposed devices are visible on Shodan today. Hunt for POST requests to /cgi-bin/luci/rpc/auth containing shell metacharacters in the username parameter, and alert on outbound wget/curl/nslookup from OT-adjacent serial converter devices. #DFIR_Radar

    Post summary

    The post confirms CVE‑2025‑67038 was actively exploited by a targeted threat cluster before disclosure, with detailed technical information on how the attack was carried out.

    10000301
    1.7K followersView on X
  • RST Cloud@rst_cloud

    #threatreport #LowCompleteness ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | 05-10-2026 Source: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure Key details below ↓ 💀Threats: Clingstun, 🎯Victims: Internet facing devices, Iot devices, Linux devices, Routers 🔓CVEs: CVE-2026-87827 \[[Vulners](https://vulners.com/cve/CVE-2026-87827)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-10915 \[[Vulners](https://vulners.com/cve/CVE-2024-10915)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2024-3721 \[[Vulners](https://vulners.com/cve/CVE-2024-3721)] - CVSS V3.1: *6.3*, - Vulners: Exploitation: True CVE-2019-7256 \[[Vulners](https://vulners.com/cve/CVE-2019-7256)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - nortekcontrol linear_emerge_essential_firmware (le1.00-06) CVE-2016-20016 \[[Vulners](https://vulners.com/cve/CVE-2016-20016)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - mvpower tv-7104he_firmware (1.8.4_115215b9) CVE-2024-32292 \[[Vulners](https://vulners.com/cve/CVE-2024-32292)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda w30e_firmware (1.0.1.25\(633\)) CVE-2021-35394 \[[Vulners](https://vulners.com/cve/CVE-2021-35394)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - realtek rtl819x_jungle_software_development_kit (le3.4.14b) CVE-2024-32281 \[[Vulners](https://vulners.com/cve/CVE-2024-32281)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac7_firmware (15.03.06.44) CVE-2024-32314 \[[Vulners](https://vulners.com/cve/CVE-2024-32314)] - CVSS V3.1: *3.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac500_firmware (2.0.1.9\(1307\)) CVE-2025-67038 \[[Vulners](https://vulners.com/cve/CVE-2025-67038)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lantronix eds5008_firmware (<2.2.0.0r1) CVE-2024-46048 \[[Vulners](https://vulners.com/cve/CVE-2024-46048)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda fh451_firmware (1.0.0.9) CVE-2023-26801 \[[Vulners](https://vulners.com/cve/CVE-2023-26801)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lb-link bl-lte300_firmware (1.0.8) CVE-2022-37055 \[[Vulners](https://vulners.com/cve/CVE-2022-37055)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink go-rt-ac750_firmware (2.00b02) CVE-2023-41011 \[[Vulners](https://vulners.com/cve/CVE-2023-41011)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - chinamobile intelligent_home_gateway_firmware (hg6543c4) CVE-2022-35555 \[[Vulners](https://vulners.com/cve/CVE-2022-35555)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - tenda w6_firmware (1.0.0.9\(4122\)) CVE-2024-10914 \[[Vulners](https://vulners.com/cve/CVE-2024-10914)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) CVE-2024-7029 \[[Vulners](https://vulners.com/cve/CVE-2024-7029)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - avtech avm1203_firmware (lefullimg-1023-1007-1011-1009) CVE-2025-34035 \[[Vulners](https://vulners.com/cve/CVE-2025-34035)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - engeniustech esr300_firmware (1.1.0.28, 1.3.1.42, 1.4.0, 1.4.1.28, 1.4.2) CVE-2024-23624 \[[Vulners](https://vulners.com/cve/CVE-2024-23624)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2022-36553 \[[Vulners](https://vulners.com/cve/CVE-2022-36553)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - hytec hwl-2511-ss_firmware (le1.05) CVE-2019-17621 \[[Vulners](https://vulners.com/cve/CVE-2019-17621)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-859_firmware (le1.05b03, 1.06b01) CVE-2026-36356 \[[Vulners](https://vulners.com/cve/CVE-2026-36356)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True CVE-2025-34037 \[[Vulners](https://vulners.com/cve/CVE-2025-34037)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-23625 \[[Vulners](https://vulners.com/cve/CVE-2024-23625)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2024-35340 \[[Vulners](https://vulners.com/cve/CVE-2024-35340)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: Unknown Soft: - tenda fh1206_firmware (1.2.0.8\(8155\)) CVE-2023-46805 \[[Vulners](https://vulners.com/cve/CVE-2023-46805)] - CVSS V3.1: *8.2*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2024-21887 \[[Vulners](https://vulners.com/cve/CVE-2024-21887)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2022-26289 \[[Vulners](https://vulners.com/cve/CVE-2022-26289)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda m3_firmware (1.0.0.12\(4856\)) CVE-2014-8361 \[[Vulners](https://vulners.com/cve/CVE-2014-8361)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-905l_firmware (le2.05b01) CVE-2021-36380 \[[Vulners](https://vulners.com/cve/CVE-2021-36380)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - sunhillo sureline (<8.7.0.1.1) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1037, T1057, T1071, T1090, T1105, T1190, T1547, T1564 🧨IOCs: - IP: 3 - File: 5 - Hash: 21 💽Software: Linux, WebRTC, Ivanti, Tenda, LB-LINK 💻Platforms: mips, arm, intel #threatreport: ClingSTUN is a Linux backdoor that exploits Internet-facing, unpatched devices and converts them into remotely controlled proxy nodes. Initial delivery was observed through exploitation of CVE-2022-36553, a command-injection vulnerability in Hytec Inter HWL-2511-SS routers. Subsequent campaigns used command injection in the EnGenius IoT cloud service (CVE-2025-34035), D-Link UPnP (CVE-2024-23625), Linear and other IoT devices, Realtek devices affected by CVE-2021-35394, TP-Link Archer AX21 devices affected by CVE-2023-1389, AVTECH AVM1203 devices affected by CVE-2024-7029, and D-Link devices affected by CVE-2024-10915. The attackers also used a buffer overflow in the `goform` name parameter across multiple device vendors. ClingSTUN downloaders move to `/tmp`, retrieve architecture-specific payloads, and execute versions for ARM, Intel 80386, MIPS, PowerPC, and AMD x86-64 systems. A later downloader scans `/proc/mounts`, unmounts selected mount points, kills associated processes, and terminates processes running from `/tmp`. The malware also enumerates `/proc`, identifies competing or suspicious processes, compares process command lines with executable names, and kills processes that fail its checks. It opens watchdog device files and uses `ioctl` to disable watchdog timers. For persistence, ClingSTUN copies itself to `/root/.cling` and `/usr/local/bin/.cling`, sets executable permissions, and appends these files to three startup-related files so they execute during boot. It clears its command-line arguments to hide activity from process-monitoring tools. When running as root, it copies selected files from `/proc/1` into `/tmp` and bind-mounts the directory over its own `/proc` entry to conceal process information. The backdoor uses UDP sockets and standard 20-byte STUN binding requests to contact public STUN services, discover externally mapped addresses and ports, and maintain NAT bindings. Earlier versions contacted 24 endpoints and required at least half to respond; a later version used 13 endpoints and required all to succeed. It periodically sends a group identifier and mapped-port data to these services. A specially formatted 20-byte operator packet can trigger remote command execution: command 1 causes the malware to establish an outbound TCP connection, receive a command, and execute it. ClingSTUN also contains hard-coded exploits for self-propagation.

    00000183
    830 followersView on X
  • Cyphere@TheCyphere
    Active Exploitation

    CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability CVE-2026- @CISACyber

    Post summary

    CISA announced adding four vulnerabilities to its Known Exploited Vulnerabilities catalog citing evidence of active exploitation, with only the CVE identifiers and a brief code‑injection description provided, and no PoC, exploit tool, patch, or debunking statement mentioned.

    0000062
    1.5K followersView on X
  • Israel@f1tym1
    Active Exploitation

    Update: CISA has formally added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog, elevating the threat's official standing and reinforcing mandatory remediation timelines for federal agencies. https://ift.tt/XZkvouM

    Post summary

    CISA has added CVE-2025-67038 to its KEV catalog, confirming it is actively exploited in the wild and mandating remediation for federal agencies.

    0000043
    1.0K followersView on X
  • DarkInvader@DarkInvaderIO
    Active Exploitation

    Lantronix EDS5000 flaw (CVE-2025-67038, CVSS 9.8): attackers reverse-engineered the patch and exploited it before public disclosure. Unauth command injection → root, on OT serial-to-IP bridges nobody inventories. Now on CISA KEV. Read here: https://buff.ly/0tC1Zca https://t.co/cdWAOledo6

    Post summary

    Lantronix EDS5000 serial‑to‑IP bridges are vulnerable to unauthenticated command injection (CVE‑2025‑67038, CVSS‑9.8). Attackers have reverse‑engineered the patch and exploited the flaw before disclosure, and the vulnerability is listed on the CISA KEV.

    0000038
    112 followersView on X
  • ✨_geeknik_//✨@geeknik
    Active Exploitation

    Patch-and-pray doesn't work in OT. Attackers reverse-engineered a Lantronix fix and exploited CVE-2025-67038 before the research even went public. Your patch is their roadmap. https://www.securityweek.com/lantronix-serial-to-ip-converter-flaw-exploited-in-attacks-after-ot-threat-warning/

    Post summary

    Attackers leveraged a reverse‑engineered Lantronix patch to exploit CVE‑2025‑67038 in OT environments before public disclosure, indicating active exploitation.

    00000271
    20.1K followersView on X
  • Polsia@polsia
    Active Exploitation

    CVE-2025-67038 | Lantronix EDS5000 (serial-to-IP bridge, firmware ≤2.1.0.0R3) Attackers inject OS commands via the username field in the HTTP RPC auth log — no creds needed. CVSS 9.8 | In KEV: Jun 23, 2026

    Post summary

    CVE-2025-67038 is an OS command injection flaw in Lantronix EDS5000 firmware that attackers can exploit by inserting commands into the username field without credentials; it is listed in KEV, indicating active exploitation, though no PoC, patch, or exploit code is disclosed.

    0000073
    23.8K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent zero-day exploits like CVE-2026-20245 (Cisco SD-WAN) &amp; CVE-2025-67038 (Lantronix EDS5000) show active network device targeting. These vulnerabilities threaten data privacy &amp; integrity in transit via interception &amp; command execution. #Cybersecurity #NetworkSecurity #ZeroDay

    Post summary

    The post highlights recent zero‑day CVEs being actively exploited against network devices, specifically targeting data privacy and integrity through interception and command execution.

    00000107
    14 followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Active Exploitation

    Recent findings reveal encrypted DNS (TLS/QUIC) still exposes critical metadata, impacting data privacy in transit. Also, active exploits target Cisco SD-WAN zero-day (CVE-2026-20245) &amp; Lantronix EDS5000 (CVE-2025-67038). Stay vigilant! #Cybersecurity #InfoSec #ZeroDay

    Post summary

    The tweet highlights that encrypted DNS still leaks metadata and reports that Cisco SD‑WAN (CVE‑2026-20245) and Lantronix EDS5000 (CVE‑2025-67038) vulnerabilities are actively being exploited in the wild.

    00000116
    14 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    CVE-2025-67038: Lantronix EDS5000にてOSコマンドインジェクションの脆弱性が報告。CVSSスコア未公開。攻撃者がルート権限で命令を実行可能。パッチ適用が急務です。

    Post summary

    Lantronix EDS5000 suffers from a root‑privilege OS command injection (CVE-2025-67038) and the vendor urgently recommends applying the patch.

    0000061
    564 followersView on X
  • Lucas@lucasverdan
    Active Exploitation

    Most people will see the headline. The real signal is what lantronix-eds5000-cve-2025-67038… CVE-2025-67038 is being exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI. 🔗 Details → https://invaders.ie/resources/blog/vulnerability/lantronix-eds5000-cve-2025-67038-active-exploitation

    Post summary

    CVE-2025-67038 is currently being actively exploited against Lantronix EDS5000 devices, enabling root command execution via OpenWRT LuCI.

    0000071
    310 followersView on X
CPE platform detail66 entries

66 of 66 entries

PartVendorProductVersionTarget SWTarget HW
HWlantronixe213f102s---
OSlantronixe213f102s_firmware---
HWlantronixe214f002s---
OSlantronixe214f002s_firmware---
HWlantronixe214f00cs---
OSlantronixe214f00cs_firmware---
HWlantronixe214g000s---
OSlantronixe214g000s_firmware---
HWlantronixe214g001s---
OSlantronixe214g001s_firmware---
HWlantronixe218f004s---
OSlantronixe218f004s_firmware---
HWlantronixe218g107s---
OSlantronixe218g107s_firmware---
HWlantronixe228g002s---
OSlantronixe228g002s_firmware---
HWlantronixe228g004s---
OSlantronixe228g004s_firmware---
HWlantronixe228g00cb28---
OSlantronixe228g00cb28_firmware---
HWlantronixe228g00cs---
OSlantronixe228g00cs_firmware---
HWlantronixeds5008---
OSlantronixeds5008_firmware---
HWlantronixeds5016---
OSlantronixeds5016_firmware---
HWlantronixeds5032---
OSlantronixeds5032_firmware---
HWlantronixg526gp12s---
OSlantronixg526gp12s_firmware---
HWlantronixg526gp17s---
OSlantronixg526gp17s_firmware---
HWlantronixg526gp1as---
OSlantronixg526gp1as_firmware---
HWlantronixg526gp1asg---
OSlantronixg526gp1asg_firmware---
HWlantronixg526gp1cs---
OSlantronixg526gp1cs_firmware---
HWlantronixg527gp22s---
OSlantronixg527gp22s_firmware---
HWlantronixg527gp27s---
OSlantronixg527gp27s_firmware---
HWlantronixg527gp2as---
OSlantronixg527gp2as_firmware---
HWlantronixg527gp2asg---
OSlantronixg527gp2asg_firmware---
HWlantronixg528gp2fs---
OSlantronixg528gp2fs_firmware---
HWlantronixg528gp2fsg---
OSlantronixg528gp2fsg_firmware---
HWlantronixg528gp2fsgc---
OSlantronixg528gp2fsgc_firmware---
HWlantronixx300f202s---
OSlantronixx300f202s_firmware---
HWlantronixx303f202s---
OSlantronixx303f202s_firmware---
HWlantronixx304g000s---
OSlantronixx304g000s_firmware---
HWlantronixx304g002s---
OSlantronixx304g002s_firmware---
HWlantronixx304g007s---
OSlantronixx304g007s_firmware---
HWlantronixx304g00as---
OSlantronixx304g00as_firmware---
HWlantronixx304g00cs---
OSlantronixx304g00cs_firmware---

Explore more