{
    "dataType": "CVE_RECORD",
    "cveMetadata": {
        "state": "PUBLISHED",
        "cveId": "CVE-2025-67038",
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "dateUpdated": "2026-09-04T20:30:00.766Z",
        "dateReserved": "2025-12-08T00:00:00.000Z",
        "datePublished": "2026-03-11T00:00:00.000Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
                "shortName": "icscert",
                "dateUpdated": "2026-09-04T20:30:00.766Z"
            },
            "title": "Lantronix EDS5000, G520, and X300 OS Command Injection",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-78",
                            "description": "CWE-78",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Lantronix",
                    "product": "EDS5000 series",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "2.1.0.0R3",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "2.2.0.0R1"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Lantronix",
                    "product": "G520 series",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2.6.0.4R6",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "2.6.0.4R6"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Lantronix",
                    "product": "X300 series",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "2.6.0.4R6",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "2.6.0.4R6"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Lantronix",
                    "product": "E210 series",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "3.21.0.0R1",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "3.21.0.0R1"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Lantronix",
                    "product": "E220 series",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "3.21.0.0R1",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "3.21.0.0R1"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>\nAn issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.\n\n</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw"
                },
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-069-02"
                },
                {
                    "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-069-02.json"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "HIGH",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.3,
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Latronix has released the following updates addressing this vulnerability. For more information, see the Latronix Vulnerability Library ( https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw ).",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Latronix has released the following updates addressing this vulnerability. For more information, see the Latronix Vulnerability Library (<a href=\"https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw\">https://www.lantronix.com/technical-support/security-updates/vulnerability-disclosure-policy/vulnerability-library/?_gl=16c8bez_upMQ.._gaMzQwNjk5ODI5LjE3ODI5MTM3NTk._ga_M2G6RLT5L3*czE3ODI5MTM3NTgkbzEkZzAkdDE3ODI5MTM3NTgkajYwJGwwJGgw</a>)."
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "EDS5000 series: Upgrade to version 2.2.0.0R1 or later. The patch can be found here: \n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "EDS5000 series: Upgrade to version 2.2.0.0R1 or later. The patch can be found here:&nbsp;<br><a href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032\">https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2538438657/Latest+Firmware+for+the+EDS5000+series+EDS5008+EDS5016+EDS5032</a>"
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "G520 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: \n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "G520 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here:&nbsp;<br><a href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528\">https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1889828865/Latest+firmware+for+the+G520+Series+G526+G526RP+G527+G528</a>"
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "X300 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here: \n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2135261185/Latest+firmware+for+the+X300+Series+X300+X303+X304",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "X300 series: Upgrade to version 2.6.0.4R6 or later. The patch can be found here:&nbsp;<br><a href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2135261185/Latest+firmware+for+the+X300+Series+X300+X303+X304\">https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/2135261185/Latest+firmware+for+the+X300+Series+X300+X303+X304</a>"
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "E210 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: \n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914404865/Latest+firmware+ePack+for+the+E210+Series+E213+E214+E215+E218+Cellular+Routers",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "E210 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here:&nbsp;<br><a href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914404865/Latest+firmware+ePack+for+the+E210+Series+E213+E214+E215+E218+Cellular+Routers\">https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914404865/Latest+firmware+ePack+for+the+E210+Series+E213+E214+E215+E218+Cellular+Routers</a>"
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "E220 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here: \n https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914437633/Latest+firmware+ePack+for+the+E220+Series+E224+E225+E228+Cellular+Routers",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "E220 series: Upgrade to version 3.21.0.0R1 or later. The patch can be found here:&nbsp;<br><a href=\"https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914437633/Latest+firmware+ePack+for+the+E220+Series+E224+E225+E228+Cellular+Routers\">https://ltrxdev.atlassian.net/wiki/spaces/LTRXTS/pages/1914437633/Latest+firmware+ePack+for+the+E220+Series+E224+E225+E228+Cellular+Routers</a>"
                        }
                    ]
                },
                {
                    "lang": "en",
                    "value": "For more information or technical assistance, contact Lantronix support (Support@lantronix.com).\n mailto:Support@lantronix.com",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "For more information or technical assistance, contact Lantronix support (Support@lantronix.com).<br><a href=\"mailto:Support@lantronix.com\">mailto:Support@lantronix.com</a>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Francesco La Spina and Stanislav Dashevskyi of Forescout Technologies reported the vulnerability for the EDS5000 series to CISA.",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Lantronix reported the vulnerability for the G520 series, X300 series, E210 series, and E220 series to CISA.",
                    "type": "finder"
                }
            ],
            "source": {
                "advisory": "ICSA-26-069-02",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.5"
            }
        },
        "adp": [
            {
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "type": "CWE",
                                "cweId": "CWE-94",
                                "lang": "en",
                                "description": "CWE-94 Improper Control of Generation of Code ('Code Injection')"
                            }
                        ]
                    }
                ],
                "references": [
                    {
                        "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038",
                        "tags": [
                            "government-resource"
                        ]
                    }
                ],
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 9.8,
                            "attackVector": "NETWORK",
                            "baseSeverity": "CRITICAL",
                            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "NONE",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-06-23T00:00:00+00:00",
                                "options": [
                                    {
                                        "Exploitation": "active"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3",
                                "id": "CVE-2025-67038"
                            }
                        }
                    },
                    {
                        "other": {
                            "type": "kev",
                            "content": {
                                "dateAdded": "2026-06-23",
                                "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-67038"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-06-24T03:55:55.179Z"
                },
                "timeline": [
                    {
                        "time": "2026-06-23T00:00:00.000Z",
                        "lang": "en",
                        "value": "CVE-2025-67038 added to CISA KEV"
                    }
                ]
            }
        ]
    },
    "dataVersion": "5.2"
}