PT-2026-24723 · Lantronix · E210 Series+7
CVE-2025-67038
·
Published
2026-03-11
·
Updated
2026-08-28
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Lantronix EDS5000 version 2.1.0.0R3
Description
The HTTP RPC module in Lantronix EDS5000 series devices contains a code injection flaw. When user authentication fails, the module executes a shell command to write logs, directly concatenating the
username parameter into the command without sanitization. This allows unauthenticated attackers to inject and execute arbitrary operating system commands with root privileges via the /cgi-bin/luci/rpc/auth endpoint. Approximately 54,500 instances have been identified globally, with nearly 32,000 devices exposed on Shodan. This issue was exploited as a zero-day starting April 5 by a threat cluster named Chaya 006, which used scanner IPs across Asia to target devices and establish callbacks to command-and-control servers.Recommendations
Apply the available security fixes to Lantronix EDS5000 version 2.1.0.0R3 immediately.
Avoid using the
username parameter in the /cgi-bin/luci/rpc/auth endpoint until the security fix is applied.Fix
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E210 Series
E220 Series
Eds5000 Series
G520 Series
Srx300 Series
Eds5008 Firmware
Eds5016 Firmware
Eds5032 Firmware