PT-2026-24723 · Lantronix · Eds5008 Firmware+2
Published
2026-03-11
·
Updated
2026-06-26
·
CVE-2025-67038
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lantronix EDS5000 version 2.1.0.0R3
Description
The HTTP RPC module in Lantronix EDS5000 series devices contains a code injection flaw. When user authentication fails, the module executes a shell command to write logs, directly concatenating the
username parameter into the command without sanitization. This allows unauthenticated attackers to inject and execute arbitrary operating system commands with root privileges via the /cgi-bin/luci/rpc/auth endpoint. Approximately 54,500 instances have been identified globally, with nearly 32,000 devices exposed on Shodan. This issue was exploited as a zero-day starting April 5 by a threat cluster named Chaya 006, which used scanner IPs across Asia to target devices and establish callbacks to command-and-control servers.Recommendations
Apply the available security fixes to Lantronix EDS5000 version 2.1.0.0R3 immediately.
Avoid using the
username parameter in the /cgi-bin/luci/rpc/auth endpoint until the security fix is applied.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eds5008 Firmware
Eds5016 Firmware
Eds5032 Firmware