IM
IronMonkey Threat Research

CVE-2025-67038 CRITICAL

Published: 2026-03-11 | Last Modified: 2026-09-08 | Status: Analyzed

Description

An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

Additional Descriptions (1)

Se descubrió un problema en Lantronix EDS5000 2.1.0.0R3. El módulo HTTP RPC ejecuta un comando de shell para escribir registros cuando la autenticación del usuario falla. El nombre de usuario se concatena directamente con el comando sin ninguna sanitización. Esto permite a los atacantes inyectar comandos arbitrarios del sistema operativo en el parámetro de nombre de usuario. Los comandos inyectados se ejecutan con privilegios de root.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 3.9

Impact Score: 5.9

Base Score: 9.3 (CRITICAL)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionNONE
Vulnerability ConfidentialityHIGH
Vulnerability IntegrityHIGH
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-78

Affected Products

Vendor Product Version Update Type
lantronix eds5008_firmware * <built-in method update of dict object at 0x7fd2a1f394c0> Operating System
lantronix eds5016_firmware * <built-in method update of dict object at 0x7fd2a1f3ad80> Operating System
lantronix eds5032_firmware * <built-in method update of dict object at 0x7fd31b2a7240> Operating System
lantronix g526gp12s_firmware * <built-in method update of dict object at 0x7fd319997f80> Operating System
lantronix g526gp17s_firmware * <built-in method update of dict object at 0x7fd2a1f39f00> Operating System
lantronix g526gp1cs_firmware * <built-in method update of dict object at 0x7fd2a1f39200> Operating System
lantronix g526gp1asg_firmware * <built-in method update of dict object at 0x7fd3423b1dc0> Operating System
lantronix g526gp1as_firmware * <built-in method update of dict object at 0x7fd386740b40> Operating System
lantronix g527gp22s_firmware * <built-in method update of dict object at 0x7fd340a1db40> Operating System
lantronix g527gp27s_firmware * <built-in method update of dict object at 0x7fd2a1f3a0c0> Operating System
lantronix g527gp2as_firmware * <built-in method update of dict object at 0x7fd2a1b43c80> Operating System
lantronix g527gp2asg_firmware * <built-in method update of dict object at 0x7fd384e09640> Operating System
lantronix g528gp2fs_firmware * <built-in method update of dict object at 0x7fd2a1b42840> Operating System
lantronix g528gp2fsg_firmware * <built-in method update of dict object at 0x7fd369e20080> Operating System
lantronix g528gp2fsgc_firmware * <built-in method update of dict object at 0x7fd36b1e7900> Operating System
lantronix x300f202s_firmware * <built-in method update of dict object at 0x7fd36bda0dc0> Operating System
lantronix x303f202s_firmware * <built-in method update of dict object at 0x7fd2a1f38740> Operating System
lantronix x304g00as_firmware * <built-in method update of dict object at 0x7fd36b404200> Operating System
lantronix x304g000s_firmware * <built-in method update of dict object at 0x7fd36b1e4040> Operating System
lantronix x304g002s_firmware * <built-in method update of dict object at 0x7fd3408d1b40> Operating System
lantronix x304g007s_firmware * <built-in method update of dict object at 0x7fd2dbe44c80> Operating System
lantronix x304g00cs_firmware * <built-in method update of dict object at 0x7fd384e08680> Operating System
lantronix e228g002s_firmware * <built-in method update of dict object at 0x7fd2a1f3bdc0> Operating System
lantronix e228g004s_firmware * <built-in method update of dict object at 0x7fd2dbe44540> Operating System
lantronix e228g00cb28_firmware * <built-in method update of dict object at 0x7fd36b9120c0> Operating System
lantronix e228g00cs_firmware * <built-in method update of dict object at 0x7fd360277680> Operating System
lantronix e213f102s_firmware * <built-in method update of dict object at 0x7fd36b407ec0> Operating System
lantronix e214f002s_firmware * <built-in method update of dict object at 0x7fd36b404b00> Operating System
lantronix e214f00cs_firmware * <built-in method update of dict object at 0x7fd369ec58c0> Operating System
lantronix e214g000s_firmware * <built-in method update of dict object at 0x7fd36b1e6200> Operating System
lantronix e214g001s_firmware * <built-in method update of dict object at 0x7fd3423b3f80> Operating System
lantronix e218f004s_firmware * <built-in method update of dict object at 0x7fd369ec7440> Operating System
lantronix e218g107s_firmware * <built-in method update of dict object at 0x7fd3423b21c0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:eds5008_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:eds5008:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:eds5016_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:eds5016:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:eds5032_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:eds5032:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g526gp12s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g526gp12s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g526gp17s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g526gp17s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g526gp1cs_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g526gp1cs:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g526gp1asg_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g526gp1asg:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g526gp1as_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g526gp1as:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g527gp22s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g527gp22s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g527gp27s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g527gp27s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g527gp2as_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g527gp2as:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g527gp2asg_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g527gp2asg:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g528gp2fs_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g528gp2fs:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g528gp2fsg_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g528gp2fsg:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:g528gp2fsgc_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:g528gp2fsgc:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x300f202s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x300f202s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x303f202s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x303f202s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x304g00as_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x304g00as:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x304g000s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x304g000s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x304g002s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x304g002s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x304g007s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x304g007s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:x304g00cs_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:x304g00cs:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e228g002s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e228g002s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e228g004s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e228g004s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e228g00cb28_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e228g00cb28:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e228g00cs_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e228g00cs:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e213f102s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e213f102s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e214f002s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e214f002s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e214f00cs_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e214f00cs:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e214g000s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e214g000s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e214g001s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e214g001s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e218f004s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e218f004s:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:lantronix:e218g107s_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:lantronix:e218g107s:-:*:*:*:*:*:*:*