
CVE-2025-67038: Lantronix EDS5000 — Remote Root Code Execution (June 2026)
CVE-2025-67038 — Lantronix EDS5000
CVE-2025-67038 is a critical severity code injection vulnerability in Lantronix EDS5000 devices. It allows remote attackers to execute arbitrary OS commands as root via crafted requests to the authentication RPC endpoint. The flaw is under active exploitation as of June 2026, with no authentication required for successful attack.
Attack Vector
Attackers exploit CVE-2025-67038 by sending specially crafted requests to the /cgi-bin/luci/rpc/auth endpoint. The threat actor "Chaya_006" has been observed leveraging this vector since April 2026. Known malicious IPs include 38.207.136.2 and 218.13.42.36. Exploitation enables full system compromise, unauthorized configuration changes, and lateral movement within the network.
Who Is at Risk
Lantronix EDS5000 devices exposed to the internet are at immediate risk. Ubiquiti UniFi OS deployments are also being targeted via related vulnerabilities (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) enabling remote code execution. Thousands of vulnerable systems remain unpatched, particularly in North America. Confirmed affected organizations include Lantronix and Ubiquiti.
Patch & Mitigate
- Patch: Apply the latest firmware update from Lantronix for EDS5000 immediately. For Ubiquiti UniFi OS, update to the fixed versions addressing CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910.
- Workaround: Restrict network access to management interfaces and RPC endpoints. Disable unnecessary remote access until patched.
- Detect: Monitor logs for requests to /cgi-bin/luci/rpc/auth, especially from IPs 38.207.136.2 and 218.13.42.36. Look for anomalous root-level command execution and unauthorized configuration changes.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploit exposed authentication endpoints to gain entry.
- TA0005 — Defense Evasion: Malicious commands are executed with root privileges, bypassing standard controls.
- TA0007 — Discovery: Attackers may enumerate internal network resources post-compromise.
Source: https://thehackernews.com/2026/06/cisa-warns-critical-lantronix-eds5000.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

