Critical Lantronix EDS5000 RCE Exploited in the Wild: CISA Orders Federal Agency Remediation
CISA has confirmed active exploitation of CVE-2025-67038, a code injection vulnerability in Lantronix EDS5000 Series devices with a CVSS score of 9.8 that enables remote code execution. Federal agencies are required to patch by June 26, 2026.