<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Lantronix</title><description>Actively exploited vulnerabilities affecting Lantronix products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/lantronix.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-67038 — Lantronix EDS5000 Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-67038</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-67038</guid><description>This vulnerability allows an attacker to inject arbitrary operating system commands through the username parameter of Lantronix EDS5000 devices. What makes this especially dangerous is that injected commands execute with root privileges, meaning a successful attacker gains full control of the affected device. EDS5000 units are serial-to-network device servers commonly used in industrial and enterprise environments, so compromise could expose connected serial devices and broader network segments.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>Lantronix</category><category>EDS5000</category></item></channel></rss>