Digital.Nhs.Uk
Critical Vulnerability CVE-2025-67038 Exploited in Lantronix Devices
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 23, 2026, CISA added CVE-2025-67038 to its KEV list, indicating active exploitation. This vulnerability affects the Lantronix EDS5000 platform, allowing unauthenticated OS command injection. Exploitation can lead to arbitrary command execution with root privileges, impacting industrial automation systems. Lantronix has released security updates for affected devices, including EDS3000PS and EDS5000. The NHS England National CSOC assesses further exploitation as highly likely. The vulnerability was first published on March 11, 2026, and a public proof of concept was released on June 25, 2026. Affected organizations are urged to apply firmware updates immediately.
Key Points: • CVE-2025-67038 allows unauthenticated OS command injection in Lantronix devices. • CISA added the vulnerability to its KEV list on June 23, 2026, indicating active exploitation. • Lantronix has released security updates for affected EDS3000PS and EDS5000 devices.