HIGHVulnerability
Verified
Global

CISA KEV: Lantronix EDS5000 — Lantronix EDS5000 Code Injection Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Analysis

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. Added to CISA Known Exploited Vulnerabilities catalog on 2026-06-23. Remediation due: 2026-06-26.

Indicators of Compromise (1)

CVE (1)
CVE-2025-67038
Source Attribution

Originally published by CISA KEV on Jun 23, 2026. Verified by: CISA.

Related Threats

MEDIUMVulnerability

Former U.S. Soldier Sentenced for Hacking and Extortion Scheme That Exposed Sensitive Data of U.S. Government Official

September 25 – U.S. Department of Justice: Cameron John Wagenius, 22, a former Army soldier who was most recently stationed in Texas, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution for conspiring to hack into telecommunications companies’ databases, access sensitive records, and extort the companies by threatening to... Source

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101075 — A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The imp...

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipulation of the argument mac leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about thi

CVE-2026-101075
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101074 — A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected elemen...

A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted

CVE-2026-101074
NIST NVD