Lantronix EDS5000 Root Command Injection – CVE-2025-67038
TL;DR: A critical flaw in Lantronix EDS5000 serial-to-IP console servers lets an unauthenticated attacker on the network run commands as root simply by putting them in the username field of a failed login. CISA has confirmed it is being exploited in the wild and ordered federal agencies to patch by 26 June 2026. If you run an EDS5008, EDS5016 or EDS5032, update the firmware to 2.2.0.0R1 now.
Key takeaways
- CVE-2025-67038 is a CVSS 9.8 critical OS command injection in Lantronix EDS5000 Series device servers – no authentication, no user interaction, root-level execution.
- The flaw lives in the HTTP RPC module: a failed-login event triggers a shell command that concatenates the attacker-controlled username without sanitisation.
- It was disclosed by Forescout’s Vedere Labs in April 2026 as part of the BRIDGE:BREAK research into serial-to-IP converters.
- CISA added it to the Known Exploited Vulnerabilities (KEV) catalogue on 23 June 2026, with a federal patch deadline of 26 June 2026.
- Fixed in firmware 2.2.0.0R1. These devices often sit on the boundary between IT and operational technology, so a compromise can be a foothold into otherwise isolated networks.
| CVSS Score | 9.8 (CVSS v3.1) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vulnerability Type | OS command injection / RCE (CWE-94; functionally CWE-78) |
| Affected Products | Lantronix EDS5000 Series (EDS5008 / EDS5016 / EDS5032) running firmware 2.1.0.0R3 and earlier |
| Attack Vector | Network — no authentication, no user interaction |
| Actively Exploited | Yes — in the wild (CISA KEV, added 23 Jun 2026) |
| Patch Available | Yes — fixed in firmware 2.2.0.0R1 |
| Disclosure Date | April 2026 (Forescout Vedere Labs, BRIDGE:BREAK) |

What is CVE-2025-67038?
CVE-2025-67038 is a critical, unauthenticated command-injection vulnerability in Lantronix EDS5000 Series device servers — the EDS5008, EDS5016 and EDS5032. These are serial-to-IP console servers: small appliances that put legacy serial-port equipment (PLCs, industrial controllers, network gear, building-management systems) onto an IP network so it can be managed remotely. Because they bridge the gap between old operational technology and modern networks, they frequently sit at sensitive choke points — and, all too often, end up exposed to the internet.
The flaw lets an attacker who can merely reach the device’s web interface execute arbitrary operating-system commands as root, without any valid credentials. It carries a CVSS v3.1 base score of 9.8. It was uncovered by Forescout’s Vedere Labs and published in April 2026 as one of 22 issues in their BRIDGE:BREAK research into serial-to-IP converters from Lantronix and Silex. On 23 June 2026, CISA added it to the Known Exploited Vulnerabilities catalogue after confirming real-world exploitation.
How the Lantronix EDS5000 exploit works
The mechanism is a textbook command injection, and an unusually clean one. When a login attempt to the device fails, the EDS5000’s HTTP RPC module writes a log entry — and it does so by shelling out to an operating-system command that includes the submitted username. The username is dropped straight into that command string with no sanitisation, escaping or validation. So instead of a username, an attacker simply supplies shell metacharacters followed by the command they want to run. The logging routine then executes the attacker’s payload, and because the device’s web stack runs with elevated privileges, the injected command runs as root.
In plain terms: the device tries to write “user bob failed to log in” to a log, but builds that log line by handing your input to a shell. Hand it a command instead of a name, and the shell runs it.
Three properties make this especially dangerous. First, it is pre-authentication — the vulnerable code path is the failed-login handler, so you reach it precisely because you do not have valid credentials. Second, it grants root, the highest privilege on the device. Third, it needs no user interaction and only network reachability to the management interface. An attacker who can see the EDS5000’s web port can take it over in a single request.
# NON-OPERATIONAL ILLUSTRATION — concept only, not a working exploit.# A failed-login request whose "username" field carries shell metacharacters# instead of a real name. The device's logging routine concatenates this value# into an OS command and executes it as root.POST /login HTTP/1.1Host: <eds5000-device>username=admin; <attacker-command-here> ;password=anything
The illustration above is deliberately incomplete — it shows where untrusted input enters a shell command, not a usable payload. The real-world impact is the same regardless of the exact syntax: full control of the console server, and through it, potential access to every serial-attached device behind it.
Is CVE-2025-67038 actively exploited?
Yes. CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalogue on 23 June 2026, which means the agency has evidence of in-the-wild exploitation against internet-facing and network-reachable EDS5000 devices. Federal Civilian Executive Branch agencies were ordered to apply the fix by 26 June 2026 — an unusually short three-day window that signals how seriously CISA is treating it.
As of 26 June 2026, there are no public details on who is exploiting the flaw or exactly how — CISA has not attributed the activity to a named actor, and no specific campaign has been published. What is confirmed is that the underlying technical details have been public since Forescout’s BRIDGE:BREAK disclosure in April 2026, giving attackers a clear roadmap to the vulnerable code path. For an unauthenticated, root-level bug in an internet-exposed appliance, that combination is more than enough to drive opportunistic scanning and exploitation.

How to fix CVE-2025-67038: remediation & mitigation
Patch: Upgrade affected EDS5000 Series devices to firmware 2.2.0.0R1 or later. This is the only complete fix. Lantronix publishes the latest EDS5000 firmware through its support portal and developer documentation.
If you cannot patch immediately:
- Remove the device’s management interface from the public internet. An EDS5000 web interface should never be directly reachable from the open internet — place it behind a firewall or VPN and restrict access to a small set of trusted management hosts.
- Apply strict network segmentation so the console server cannot be reached from general user or guest networks, and cannot freely reach the rest of your environment if it is compromised.
- Use an allow-list (by source IP) on any firewall or access-control list governing the management port, and disable remote management entirely if it is not required.
After patching: Treat any device that was internet-exposed before patching as potentially compromised. Because exploitation grants root, attackers may have altered configuration, planted persistence, or pivoted to attached serial equipment. Review device configuration against a known-good baseline, rotate any credentials stored on or reachable through the device, reset it to factory defaults and re-provision from trusted firmware where feasible, and audit the equipment behind it.
Detection / IOCs: No vendor-published indicators of compromise or detection signatures were available at the time of writing. In the absence of specific IOCs, hunt for the behavioural traces of command injection: unexpected outbound connections from the device, anomalous processes or configuration changes, and unusual or malformed entries in authentication logs — particularly login attempts with shell metacharacters in the username field. Monitor north-south traffic to and from these appliances closely.
Frequently asked questions
How serious is CVE-2025-67038?
Very. At CVSS 9.8 it is in the top severity band. It requires no authentication and no user interaction, and it yields root-level code execution — the maximum impact on an affected device. CISA’s three-day federal patch deadline underlines the urgency.
Which devices are affected?
Lantronix EDS5000 Series console servers — the EDS5008, EDS5016 and EDS5032 — running firmware 2.1.0.0R3 and earlier. The fix is in firmware 2.2.0.0R1.
Is there a patch?
Yes. Updating to firmware 2.2.0.0R1 or later remediates the flaw. There is no partial software fix short of upgrading, so patching is the priority; network isolation is only an interim mitigation.
Why is a “serial-to-IP converter” such a big deal?
These appliances bridge legacy serial equipment — often industrial controllers and other operational-technology gear — onto IP networks. Compromising one can hand an attacker a foothold in environments that are otherwise hard to reach, making them a high-value target despite their modest appearance.
Sources & further reading
- CISA — CISA Adds Four Known Exploited Vulnerabilities to Catalog (23 June 2026)
- CISA — Known Exploited Vulnerabilities Catalog
- The Hacker News — CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
- Security Affairs — CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its KEV catalog
- GitHub Advisory Database — CVE-2025-67038 (GHSA-55gq-23mv-cw8r)
- MITRE CVE record — CVE-2025-67038
- The Hacker News — 22 BRIDGE:BREAK flaws expose 20,000+ serial-to-IP devices
- Lantronix — Latest Firmware for the EDS5000 series
ZeroDayHub tracks critical vulnerabilities as they break. Subscribe for updates.





Leave a Reply