Skip to content
CC-4801 - Exploitation of Critical Vulnerability in Lantronix Serial-to

CC-4801 - Exploitation of Critical Vulnerability in Lantronix Serial-to

Digital.Nhs.Uk •[email protected] (NHS Digital) • June 25, 2026

Successful exploitation of CVE-2025-67038 could lead to unauthenticated OS command injection

Successful exploitation of CVE-2025-67038 could lead to unauthenticated OS command injection

The following platforms are known to be affected:

Lantronix Serial-to-Ethernet Device Servers

Exploitation of CVE-2025-67038

The US Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerability CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) Catalog.

The NHS England National CSOC assesses further exploitation as highly likely.

Lantronix has released security updates to address vulnerabilities in EDS3000PS and EDS5000 Device Servers. Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication and execute code with root privileges .

Exploitation of CVE-2025-67038 has been reported in the wild.

5 vulnerabilities affect EDS5000 Series devices:

3 vulnerabilities affect EDS300PS Series devices:

Affected organisations are encouraged to review CISA's ICS Advisory icsa-26-069-02 and apply the relevant firmware updates as soon as possible.

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authantication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Last edited: 25 June 2026 2:28 pm