# Critical Lantronix Vulnerability Exploited in Wild; OT Environments at Risk


A remote code execution vulnerability affecting Lantronix serial-to-IP device servers is being actively exploited in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed this week. The flaw, tracked as CVE-2025-67038, allows unauthenticated attackers to execute arbitrary commands with root-level privileges, potentially giving adversaries full control of critical infrastructure devices and a foothold to launch lateral network attacks.


CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, and mandated that federal agencies patch or mitigate the issue by June 26. The urgency reflects the severity of the threat: serial-to-IP converters are ubiquitous in industrial control systems, healthcare facilities, and other operational technology (OT) environments where they manage connections to legacy serial devices that cannot be directly networked.


## The Threat: Unauthenticated Command Injection


CVE-2025-67038 is a command injection vulnerability in the Lantronix EDS5000 series that enables attackers to inject malicious OS commands through the device's username parameter. Because the vulnerability requires no authentication, an attacker with network access to the device can exploit it immediately.


Technical Details:

  • CVSS Score: High severity (exact score not disclosed in initial reports)
  • Attack Vector: Network-based, unauthenticated
  • Privilege Level: Commands execute with root privileges
  • Attack Complexity: Low — no special conditions required
  • Impact: Complete device compromise and lateral network access

  • Once successfully exploited, the attacker gains complete control over the serial-to-IP converter, which serves as a bridge between modern IP networks and older serial devices. This foothold can be leveraged to:


  • Establish persistent access through remote command and control (C2) channels
  • Pivot laterally to other systems connected to the same network segment
  • Manipulate industrial processes by altering sensor readings or device communications
  • Deploy malware for long-term persistence or destructive purposes
  • Exfiltrate sensitive data through the compromised device

  • The risk is particularly acute in environments where serial devices control critical functions—power distribution, HVAC systems, manufacturing equipment, or medical monitoring devices.


    ## Background and Context: BRIDGE:BREAK Aftermath


    CVE-2025-67038 is one of 20 vulnerabilities disclosed in April 2026 as part of the BRIDGE:BREAK research initiative, led by cybersecurity firm Forescout. The research exposed critical weaknesses in serial-to-IP converter products from multiple vendors, including Lantronix and Silex, highlighting a systematic security gap in industrial infrastructure.


    The Forescout researchers went beyond simply disclosing the vulnerabilities—they demonstrated proof-of-concept attack scenarios showing how these flaws could be weaponized against industrial and healthcare environments. In their demonstrations, researchers showed how attackers could:


  • Manipulate sensor readings to conceal dangerous conditions that would normally trigger alarms or alerts
  • Trigger false alerts or operational disruptions
  • Deploy malicious firmware to industrial devices, potentially causing physical damage or patient harm in healthcare settings

  • The scope of BRIDGE:BREAK was intentionally broad, reflecting the researchers' concern that serial-to-IP converters represent a systematic vulnerability across multiple product lines and verticals. Two months after public disclosure, real-world exploitation confirms those concerns were justified.


    ## Attack Scenarios and Implications


    Security firm Aviatrix has outlined how a successful CVE-2025-67038 exploitation could unfold in practice:


    1. Initial Compromise: Attacker identifies an exposed Lantronix EDS5000 device and exploits the command injection vulnerability to execute code with root privileges.


    2. Persistence and C2: The attacker establishes a reverse shell or remote command and control channel, ensuring continued access even if the initial connection is severed.


    3. Lateral Movement: With a foothold in the OT network, the attacker scans for other systems—engineering workstations, supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), and other industrial devices—and begins reconnaissance.


    4. Data Exfiltration: Sensitive operational data, configuration files, or proprietary information is harvested through the compromised serial-to-IP device.


    5. Operational Disruption: In the worst-case scenario, the attacker modifies configurations, deploys sabotage malware, or directly interferes with device communications to cause downtime or physical consequences.


    In healthcare environments specifically, this attack chain could have life-threatening implications. Serial devices in hospitals often manage infusion pumps, ventilators, patient monitors, and other critical care equipment. An attacker capable of manipulating sensor readings or device communications could theoretically obscure dangerous conditions—such as a patient's declining vital signs or equipment malfunction—from clinical staff.


    ## Scope and Exposure: A Large and Dispersed Target


    According to search engine data from ZoomEye, thousands of Lantronix devices are directly exposed to the internet. While not all of these are vulnerable to CVE-2025-67038 (the EDS5000 series specifically is affected), the sheer number indicates a widespread deployment and a potentially large attack surface.


    The geographic distribution is notable: a majority of exposed Lantronix devices are located in the United States, suggesting that U.S. organizations—including critical infrastructure operators, healthcare facilities, and manufacturers—are at elevated risk.


    However, the true scope of vulnerable systems is likely underestimated by internet-facing device counts alone. Many organizations operate serial-to-IP converters on isolated or segmented networks, protecting them from direct external exploitation. Nevertheless, these internal systems remain vulnerable to:


  • Insider threats with network access
  • Supply chain compromise if the devices are pre-configured by vendors
  • Lateral movement by attackers already inside the network through other compromised systems

  • ## Recommendations for Organizations


    Organizations dependent on serial-to-IP converters should prioritize the following actions:


    ### Immediate Actions (Within 48 Hours)

  • Identify and inventory all Lantronix EDS5000 and similar serial-to-IP devices on your network
  • Audit network access to these devices; disable internet-facing exposure where possible
  • Check logs for signs of exploitation (suspicious authentication attempts, unexpected command execution, unusual process activity)

  • ### Short-Term Mitigations (Within 1–2 Weeks)

  • Apply patches from Lantronix when available; monitor vendor advisories closely
  • Implement network segmentation: Restrict access to serial-to-IP converters to only the systems and users that require it
  • Enable authentication and access controls: Where supported, enforce strong credentials and limit administrative access
  • Monitor the KEV catalog: CISA's list will be updated as more information emerges regarding exploitation

  • ### Long-Term Strategy

  • Maintain vendor relationships: Establish direct communication channels with Lantronix and other OT equipment manufacturers to receive security updates
  • Conduct security assessments: Engage third-party assessors to evaluate the security posture of your OT network and serial device integrations
  • Develop incident response plans: Ensure your organization has procedures in place to detect, isolate, and remediate compromised serial-to-IP devices
  • Plan for legacy device replacement: Where feasible, migrate away from serial-based architectures toward modern, secure alternatives with built-in authentication and encryption

  • ---


    ## HackWire Analysis


    The timing of real-world exploitation—just two months after BRIDGE:BREAK went public—reflects a troubling pattern in OT security. Unlike software vulnerabilities that circulate in consumer and enterprise environments, industrial flaws often persist unpatched for years because OT systems prioritize availability and stability over rapid patching. When a researcher publicly demonstrates an industrial vulnerability, the window for opportunistic exploitation is brief but critical: adversaries rush to weaponize the flaw before defenders can even detect widespread exposure.


    What makes CVE-2025-67038 particularly dangerous is that it targets a convergence point—the serial-to-IP bridge—that sits between legacy OT equipment and modern networks. These devices were often deployed before security best practices evolved, and they frequently lack update mechanisms entirely. An organization might have diligently patched its firewalls, endpoint protection, and cloud infrastructure while leaving a critical OT gateway completely undefended.


    The healthcare implications deserve special attention. The Forescout researchers specifically demonstrated how sensor manipulation could conceal dangerous conditions in clinical environments. In June 2024, a hospital ransomware attack in Dallas forced emergency protocols when network compromise threatened patient care systems. A similar scenario triggered by a compromised serial-to-IP device—where monitoring systems report false normal readings while a patient deteriorates—could result in delayed intervention with catastrophic outcomes.


    The federal mandate for federal agencies to patch by June 26 is a clear signal of urgency, but it applies only to government networks. Critical infrastructure operators in the private sector—hospitals, power utilities, water systems—have no such deadline. Many will likely not prioritize the vulnerability until a public breach report forces their hand.


    The real story here is not the vulnerability itself, but the visibility gap: thousands of serial-to-IP devices are exposed on the internet, but most organizations don't know where theirs are or whether they're vulnerable. That asymmetry between attacker capability and defender awareness is exactly where exploitation thrives.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)