# Critical Flaws in Lantronix and Ubiquity Infrastructure Devices Under Active Attack—CISA Orders Immediate Patching
## The Threat
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent warnings of active, in-the-wild exploitation targeting critical security vulnerabilities in two widely deployed infrastructure device families: Lantronix EDS5000 Series serial-to-IP converters and Ubiquity UniFi OS network management appliances. These devices are common fixtures in industrial control systems, network operations centers, and distributed enterprise environments—making the compromise of even a single device a potential springboard for broader network infiltration.
The Lantronix vulnerability stems from a code injection flaw in the HTTP RPC module that handles user authentication logging. When authentication fails, the system executes a shell command to write logs, but critically, the username parameter is concatenated directly into the command without any sanitization or input validation. This allows attackers to inject arbitrary OS commands that execute with root privileges—the highest level of system access. An unauthenticated attacker can leverage this flaw to gain complete control over the device, making it an exceptionally dangerous entry point into an organization's network.
The Ubiquity vulnerabilities are equally concerning because they can be chained together into a single attack chain that grants full root access to UniFi OS devices in a single request, as demonstrated by security researchers at Bishop Fox. Ubiquity devices frequently serve as centralized network management and control points, meaning a successful compromise could enable an attacker to pivot laterally across an entire network infrastructure. CISA has set an aggressive patching deadline of June 26, 2026, for Federal agencies, signaling the severity of active threat activity.
## Severity and Impact
| Aspect | Details |
|--------|---------|
| Primary Vulnerability (Lantronix) | CVE-2025-67038 |
| CVSS Score | 9.8 (Critical) |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack Complexity | Low—no special tools or knowledge required |
| Authentication Required | None—unauthenticated remote exploitation possible |
| Primary Vulnerability (Ubiquity) | CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 (chain) |
| CVSS Scores | All maximum severity |
| Authentication Required | Network access required; no authentication needed after initial network compromise |
| Impact | Arbitrary code execution, unauthorized system modifications, sensitive data access, lateral movement |
## Affected Products
Lantronix Serial-to-IP Converters:
Ubiquity UniFi OS Devices:
## Mitigations
Immediate Actions:
Network Segmentation:
Monitoring and Detection:
Alternative Controls (if patching is delayed):
## References
---
## HackWire Analysis
The near-simultaneous disclosure of critical flaws in Lantronix and Ubiquity devices reveals a troubling pattern in infrastructure security: devices that are supposed to *enable* network management are themselves becoming liabilities. These aren't niche products—EDS5000 converters are deployed across manufacturing floors, power grids, and data centers where they translate serial protocols to IP, making them invisible but essential. Ubiquity's UniFi OS devices are even more ubiquitous, with thousands of organizations worldwide relying on them as the nervous system of their networks.
What makes this worse is the exploit mechanics. The Lantronix flaw doesn't require authentication, doesn't require complex exploitation, and doesn't require specialized tools. An attacker needs only to send an HTTP request with a crafted username field. This is the kind of flaw that commodity malware frameworks will weaponize within days if they haven't already. The Ubiquity chain, meanwhile, is particularly dangerous because it demonstrates how seemingly individual vulnerabilities can be orchestrated into a devastating attack sequence—a lesson that defenders at thousands of organizations need to internalize.
The CISA deadline for federal agencies (June 26, 2026) is only two days from the time this advisory was issued, suggesting either that exploitation has been underway for weeks undetected, or that CISA has intelligence indicating imminent deployment at scale. Either way, organizations should not wait for their sector-specific agency to issue guidance. If you operate EDS5000 or UniFi OS devices—particularly in critical infrastructure, healthcare, financial services, or manufacturing—treat this as a code-red incident. These devices often lack visibility in asset inventories and update procedures. Find them. Patch them. Verify the patch took effect. The margin for error is zero.
— HackWire Editorial
## Related Coverage