CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
Federal Civilian Executive Branch (FCEB) agencies are urged to implement the remedies by June 26, 2026, after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on Tuesday about the active exploitation of a major security hole affecting Lantronix EDS5000 Series devices.
The vulnerability in question is code injection bug CVE-2025-67038 (CVSS score: 9.8), which could lead to the execution of arbitrary instructions with elevated privileges.
The vulnerability's description on CVE.org states that when the user's authentication fails, the HTTP RPC module runs a shell command to write logs. Without any sanitization, the username and the command are concatenated straight. Attackers can now insert any OS command into the username parameter. Root privileges are...



