CISA Alerts on Active Exploitation of Serious Lantronix EDS5000 Vulnerability

CISA has issued a warning regarding a significant vulnerability in Lantronix EDS5000 devices, urging immediate action from federal agencies.

3 min readCybersecurity

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert concerning a severe security vulnerability affecting the Lantronix EDS5000 Series. This flaw, identified as CVE-2025-67038, has a high CVSS score of 9.8, indicating its potential severity. CISA has reported that this vulnerability is currently being exploited in the wild, prompting an urgent call for action from Federal Civilian Executive Branch (FCEB) agencies. These agencies are advised to implement the necessary security updates by June 26, 2026, to mitigate the risks associated with this flaw. The vulnerability allows for code injection, which could lead to unauthorized execution of commands, posing a significant threat to the integrity and security of affected systems. Organizations utilizing these devices are strongly encouraged to prioritize this update to safeguard their infrastructure from potential attacks.

Cybersecurity