PT-2026-24723 · Lantronix · E210 Series+7

CVE-2025-67038

·

Published

2026-03-11

·

Updated

2026-08-28

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Lantronix EDS5000 version 2.1.0.0R3
Description The HTTP RPC module in Lantronix EDS5000 series devices contains a code injection flaw. When user authentication fails, the module executes a shell command to write logs, directly concatenating the username parameter into the command without sanitization. This allows unauthenticated attackers to inject and execute arbitrary operating system commands with root privileges via the /cgi-bin/luci/rpc/auth endpoint. Approximately 54,500 instances have been identified globally, with nearly 32,000 devices exposed on Shodan. This issue was exploited as a zero-day starting April 5 by a threat cluster named Chaya 006, which used scanner IPs across Asia to target devices and establish callbacks to command-and-control servers.
Recommendations Apply the available security fixes to Lantronix EDS5000 version 2.1.0.0R3 immediately. Avoid using the username parameter in the /cgi-bin/luci/rpc/auth endpoint until the security fix is applied.

Fix

Code Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67038

Affected Products

E210 Series
E220 Series
Eds5000 Series
G520 Series
Srx300 Series
Eds5008 Firmware
Eds5016 Firmware
Eds5032 Firmware