www.securityweek.com 6/25/2026, 12:01:40 PM · external

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

A vulnerability tracked as CVE-2025-67038 affecting Lantronix EDS5000 device servers is being actively exploited, as reported by CISA. The flaw allows unauthenticated attackers to execute arbitrary OS commands with root privileges, posing significant risks to operational technology and healthcare systems. This vulnerability is part of a larger set of serial-to-IP product vulnerabilities known collectively as BRIDGE:BREAK, which can impact sensor readings and disrupt services.

Although CISA included CVE-2025-67038 in its Known Exploited Vulnerabilities catalog, there are currently no public reports of related attacks. Cybersecurity firm Aviatrix has detailed potential attack scenarios involving lateral movement within networks, sensitive data exfiltration, and operational disruptions.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline