CISA says attackers are exploiting Lantronix EDS5000 command-injection flaw CVE-2025-67038

CISA says hackers are actively exploiting a critical flaw in Lantronix EDS5000 serial-to-Ethernet servers, and affected organizations should patch quickly. The bug, CVE-2025-67038, affects EDS5000 firmware 2.1.0.0R3 and stems from unsanitized input in the HTTP remote-procedure-call module, allowing remote root-level command injection; Lantronix says users should upgrade to version 2.2.0.0R1.
Why it matters: Organizations using these device-management servers could be exposed to full remote takeover if they have not updated. This is urgent because CISA has confirmed exploitation in the wild and federal agencies have a three-day remediation deadline.

Sources

Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
Eduard Kovacs 2026.06.25 96% relevant
This article updates the same event by tying the exploited flaw to the earlier BRIDGE:BREAK OT research, noting CISA added it to KEV on June 23 with a June 26 remediation deadline for federal agencies, and adding context on possible OT and healthcare impact plus internet exposure.
CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
info@thehackernews.com (The Hacker News) 2026.06.24 99% relevant
This article appears to report the same CISA warning about active exploitation of the Lantronix EDS5000 flaw, reinforcing the exploitation status and urgency to patch or mitigate affected serial-to-Ethernet servers.
CISA warns of max severity Ubiquiti flaws exploited in attacks
Bill Toulas 2026.06.24 100% relevant
The article appears to be the first tracked item here tying CVE-2025-67038 in Lantronix EDS5000 to CISA-confirmed active exploitation and KEV inclusion.
← Back to all stories