boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-67038

Lantronix EDS5000, G520, and X300 OS Command Injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   H   H   H    9.3   .1926   97.3   YES
AFFECTED
  Product         Versions     Fixed
  EDS5000 series  unspecified  2.2.0.0R1
  G520 series     unspecified  2.6.0.4R6
  X300 series     unspecified  2.6.0.4R6
  E210 series     unspecified  3.21.0.0R1
  E220 series     unspecified  3.21.0.0R1
TIMELINE
  Dec 8   Reserved by mitre
  Mar 11  Published (CNA: mitre)
  Jun 23  Added to CISA KEV, remediation due 2026-06-26
  Jun 27  DUE DATE PASSED — CVE-2025-67038 (Lantronix EDS5000). CISA remediation deadline was June 26, 2026; still in catalog.
  Sep 4   PATCH SHIPPED — CVE-2025-67038 (Lantronix EDS5000 series). Fixed in EDS5000 series 2.2.0.0R1.
  Sep 4   RESCORED — CVE-2025-67038 (Lantronix EDS5000 series). CVSS 9.8 → 9.3 (NVD).
CWE-78 · CNA: mitre · CVSS v4.0 · 4 references · NVD status: Analyzed · KEV due June 26, 2026

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Lifecycle

Complete event history — 6 events, chronological
DateEventDetail
December 8, 2025ReservedReserved by mitre
March 11, 2026PublishedPublished (CNA: mitre)
June 23, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-06-26
June 27, 2026DUE DATE PASSEDDUE DATE PASSED — CVE-2025-67038 (Lantronix EDS5000). CISA remediation deadline was June 26, 2026; still in catalog.
September 4, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2025-67038 (Lantronix EDS5000 series). Fixed in EDS5000 series 2.2.0.0R1.
September 4, 2026RESCOREDRESCORED — CVE-2025-67038 (Lantronix EDS5000 series). CVSS 9.8 → 9.3 (NVD).

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LantronixEDS5000 series——2.2.0.0R1
LantronixG520 series——2.6.0.4R6
LantronixX300 series——2.6.0.4R6
LantronixE210 series——3.21.0.0R1
LantronixE220 series——3.21.0.0R1

Weaknesses

CWE-78

References (4)

Related

Authoritative record: CVE-2025-67038 at cve.org

Vendors: lantronix

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-67038 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.