U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-67038 | Unauthenticated Root Command Injection in Lantronix EDS5000 Device Servers CVE-2025-67038 is an OS command injection flaw (CWE-78) in the HTTP RPC module of Lantronix EDS5000 series device servers, with firmware 2.1.0.0R3 confirmed affected. When a login attempt fails, the module writes a log entry by building a shell command that directly concatenates the username from the request without any sanitization, so an attacker who sends a crafted username in an authentication request gets their commands appended to it. Because the log-writing command runs as root, an unauthenticated, network-reachable attacker gains full command execution with the highest privileges on the device. Any organization running network-exposed Lantronix EDS5000 device/console servers (EDS5008, EDS5016, EDS5032, and the G526/G527-series variants) is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-06-23 and reports it is being actively exploited; the EPSS score of 19.3% (97th percentile) reflects a high near-term exploitation risk. Do: Upgrade EDS5000-series firmware to a patched release per Lantronix's guidance, since no fixed version is specified in the available data and 2.1.0.0R3 is confirmed vulnerable; if patching is not yet possible, restrict HTTP access to the device's management interface at the network level. Federal agencies must apply vendor mitigations per CISA BOD 26-04 requirements following the 2026-06-23 KEV listing. Check device logs and configs for signs of compromise, since successful injection yields root-level command execution. | 9.3 | 19% | KEV |
| moderate≈ several thousand internet-exposed devices (public reporting on related research cites thousands of exposed Lantronix/Silex serial-to-Ethernet devices) | |
| CVE-2026-34910 | Unauthenticated Command Injection in Ubiquiti UniFi OS Devices CVE-2026-34910 is an improper input validation flaw (CWE-20) in Ubiquiti UniFi OS that allows command injection on affected gateways and network video recorders. A malicious actor with network access to the device can send crafted, unvalidated input that triggers arbitrary command execution, with no privileges or user interaction required (CVSS 3.1 base score 10.0, network vector, scope changed). Successful exploitation grants full control of the device — high confidentiality, integrity, and availability impact — and can serve as a foothold into the attached network. Affected products span the UniFi gateway and recording line: UniFi OS Server, Cloud Gateway Industrial, Dream Machine/Pro/Special Edition/Pro Max, Enterprise Fortress Gateway, Dream Wall, Dream Router and Dream Router 7, UniFi Express 7, and the UniFi Network Video Recorder. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-06-23, public reporting describes in-the-wild exploitation being used to build a Mirai botnet, and EPSS estimates an 87.5% chance of exploitation within 30 days. Do: Upgrade all listed UniFi OS devices to the fixed firmware in Ubiquiti's June 2026 security advisory (consult the vendor advisory for exact fixed versions per product), and per CISA BOD 26-04 patch within the required window or discontinue use of affected cloud-reachable assets. Restrict device management interfaces (UniFi Network UI, SSH, API) to trusted networks and audit internet-facing gateways for signs of compromise, including Mirai botnet traffic or unexpected outbound connections. | 10.0 | 87% | KEV PoC |
| mass≈1M+ UniFi gateways/NVRs deployed worldwide, with on the order of hundreds of thousands internet-exposed |
Full article344 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities (KEV) catalog.
The two flaws added to the catalog are:
- CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability
- CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability
- CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability
- CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability
The first flaw, tracked as CVE-2025-67038 (CVSS score: N/A), is a code injection vulnerability in the Lantronix EDS5000 (version 2.1.0.0R3). The vulnerability exists because the HTTP RPC module fails to sanitize the username parameter before concatenating it into a shell command for logging failed authentication attempts, allowing an attacker to execute arbitrary OS commands with root privileges.
The second flaw, tracked as CVE-2026-34908 (CVSS Base Score: 10.0 CRITICAL), is an improper access control vulnerability in Ubiquiti UniFi OS devices. A malicious actor with network access can exploit this to make unauthorized changes to the system.
The third flaw, tracked as CVE-2026-34909 (CVSS score: N/A), involves a path traversal vulnerability impacting Ubiquiti UniFi OS. While specific NVD enrichment for this entry is limited, it is associated with the same security advisory bulletin (Security Advisory Bulletin 064) as the other UniFi OS vulnerabilities.
The fourth flaw, tracked as CVE-2026-34910 (CVSS Base Score: 10.0 CRITICAL), is an improper input validation vulnerability found in UniFi OS devices. A network-adjacent malicious actor can exploit this vulnerability to execute a Command Injection.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to urgently fix the vulnerabilities by June 26, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/194142/security/u-s-cisa-adds-ubiquiti-unifi-os-and-lantronix-eds5000-plugin-flaws-to-its-known-exploited-vulnerabilities-catalog.html