CVE-2025-67038
The Lantronix EDS5000 contains a code injection vulnerability that is currently being actively exploited in the wild.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's disclosures concentrate on network edge and enterprise communications platforms, led by multiple Ubiquiti UniFi OS flaws, a Cisco Unified Communications Manager defect, and PTC Windchill/FlexPLM. No new critical-rated (CVSS 9.0+) CVEs were recorded, down from 1 the prior day, while high-priority CVEs fell to 24 from 55, a 56% decrease. Notable entries include CVE-2026-34910, CVE-2026-34909, and CVE-2026-34908 affecting Ubiquiti UniFi OS, CVE-2026-20230 in Cisco Unified CM, and CVE-2026-12569 in PTC Windchill and FlexPLM, all scored 9.5. Six of these vulnerabilities carry confirmed active exploitation, spanning network appliances, IoT device servers, and PLM systems. No patches were available across the disclosed set at publication time, so affected organizations should prioritize monitoring and compensating controls until vendor fixes ship.
Immediate action: Prioritize Ubiquiti UniFi OS, Cisco Unified Communications Manager, PTC Windchill/FlexPLM, and Lantronix EDS5000 deployments, as these carry actively exploited vulnerabilities. With no patches currently available, restrict network exposure of these systems, apply vendor-recommended mitigations, and increase monitoring until fixes are released.
The Lantronix EDS5000 contains a code injection vulnerability that is currently being actively exploited in the wild.
An improper input validation flaw in Ubiquiti UniFi OS enables network-adjacent attackers to execute arbitrary commands on the underlying system.
A path traversal vulnerability in Ubiquiti UniFi OS allows network-adjacent attackers to read sensitive system files and potentially compromise user accounts.
An improper access control vulnerability in Ubiquiti UniFi OS devices allows network-adjacent attackers to modify system configurations without authorization.
PTC Windchill and FlexPLM are vulnerable to improper input validation, allowing for potential exploitation. This vulnerability is confirmed as actively exploited in the wild.
A server-side request forgery (SSRF) vulnerability in Cisco Unified Communications Manager allows unauthenticated remote attackers to perform arbitrary file operations and escalate privileges to root.
A high-severity security vulnerability has been identified in the yashpokharna2555 Restaurant Management System, potentially allowing for unauthorized system impact.
A security vulnerability exists in the libssh2 library, potentially impacting systems relying on this component for secure shell communication.
A critical vulnerability has been discovered in the D-Link DCS-935L network camera, potentially allowing attackers to gain unauthorized access to the device.
A security vulnerability has been identified in the Wavlink WL-NU516U1-A device firmware, potentially allowing unauthorized system impact.
A security vulnerability has been identified in Tenda JD12L firmware, which may allow for unauthorized system manipulation.
A security flaw has been discovered in the Tenda JD12L router firmware that could potentially lead to unauthorized system access.
A critical security vulnerability has been identified in the Tenda JD12L router, potentially allowing for unauthorized system access or control.
A security vulnerability has been detected in the Tenda JD12L router, requiring immediate investigation and remediation to prevent potential exploitation.
A security vulnerability has been detected in the Tenda JD12L router, which requires immediate attention to protect network integrity.
Hitachi Virtual Storage Platform maintenance utilities contain an improper authorization vulnerability that may allow unauthorized access.
A security vulnerability exists in Feehi CMS up to version 2 that could lead to unauthorized system impacts.
The Hanwang e-Face General Management Platform version 6 contains a security vulnerability that may expose the system to unauthorized access.
A security weakness has been identified in the itsourcecode Baptism Information Management System that could potentially allow for unauthorized system interaction.
A security vulnerability has been identified within the itsourcecode Baptism Information Management System that may pose risks to system security.
The O+ Connect IPC service fails to authenticate clients, allowing external applications to escalate privileges and perform sensitive actions.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System that requires immediate attention from system administrators.
A security vulnerability has been identified in the YunaiV ruoyi-vue-pro platform, necessitating immediate review and remediation by security teams.
A security flaw has been identified in the SourceCodester Class and Exam Timetabling System, requiring swift remediation to maintain system security.
A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System that may expose the application to unauthorized access or manipulation.
A security weakness has been identified in the ANTLR4 parser generator, potentially impacting applications that rely on its framework for processing input data.
A vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, which may allow attackers to exploit flaws in the application's handling of user requests.
A security flaw has been discovered in the SourceCodester Class and Exam Timetabling System, potentially exposing the application to unauthorized exploitation.
A vulnerability has been identified within the SourceCodester Class and Exam Timetabling System that may compromise application security.
A security vulnerability has been determined in the SourceCodester Class and Exam Timetabling System, requiring administrative attention.