# Critical Lantronix Vulnerability Exploited in Wild; OT Environments at Risk
A remote code execution vulnerability affecting Lantronix serial-to-IP device servers is being actively exploited in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed this week. The flaw, tracked as CVE-2025-67038, allows unauthenticated attackers to execute arbitrary commands with root-level privileges, potentially giving adversaries full control of critical infrastructure devices and a foothold to launch lateral network attacks.
CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, and mandated that federal agencies patch or mitigate the issue by June 26. The urgency reflects the severity of the threat: serial-to-IP converters are ubiquitous in industrial control systems, healthcare facilities, and other operational technology (OT) environments where they manage connections to legacy serial devices that cannot be directly networked.
## The Threat: Unauthenticated Command Injection
CVE-2025-67038 is a command injection vulnerability in the Lantronix EDS5000 series that enables attackers to inject malicious OS commands through the device's username parameter. Because the vulnerability requires no authentication, an attacker with network access to the device can exploit it immediately.
Technical Details:
Once successfully exploited, the attacker gains complete control over the serial-to-IP converter, which serves as a bridge between modern IP networks and older serial devices. This foothold can be leveraged to:
The risk is particularly acute in environments where serial devices control critical functions—power distribution, HVAC systems, manufacturing equipment, or medical monitoring devices.
## Background and Context: BRIDGE:BREAK Aftermath
CVE-2025-67038 is one of 20 vulnerabilities disclosed in April 2026 as part of the BRIDGE:BREAK research initiative, led by cybersecurity firm Forescout. The research exposed critical weaknesses in serial-to-IP converter products from multiple vendors, including Lantronix and Silex, highlighting a systematic security gap in industrial infrastructure.
The Forescout researchers went beyond simply disclosing the vulnerabilities—they demonstrated proof-of-concept attack scenarios showing how these flaws could be weaponized against industrial and healthcare environments. In their demonstrations, researchers showed how attackers could:
The scope of BRIDGE:BREAK was intentionally broad, reflecting the researchers' concern that serial-to-IP converters represent a systematic vulnerability across multiple product lines and verticals. Two months after public disclosure, real-world exploitation confirms those concerns were justified.
## Attack Scenarios and Implications
Security firm Aviatrix has outlined how a successful CVE-2025-67038 exploitation could unfold in practice:
1. Initial Compromise: Attacker identifies an exposed Lantronix EDS5000 device and exploits the command injection vulnerability to execute code with root privileges.
2. Persistence and C2: The attacker establishes a reverse shell or remote command and control channel, ensuring continued access even if the initial connection is severed.
3. Lateral Movement: With a foothold in the OT network, the attacker scans for other systems—engineering workstations, supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), and other industrial devices—and begins reconnaissance.
4. Data Exfiltration: Sensitive operational data, configuration files, or proprietary information is harvested through the compromised serial-to-IP device.
5. Operational Disruption: In the worst-case scenario, the attacker modifies configurations, deploys sabotage malware, or directly interferes with device communications to cause downtime or physical consequences.
In healthcare environments specifically, this attack chain could have life-threatening implications. Serial devices in hospitals often manage infusion pumps, ventilators, patient monitors, and other critical care equipment. An attacker capable of manipulating sensor readings or device communications could theoretically obscure dangerous conditions—such as a patient's declining vital signs or equipment malfunction—from clinical staff.
## Scope and Exposure: A Large and Dispersed Target
According to search engine data from ZoomEye, thousands of Lantronix devices are directly exposed to the internet. While not all of these are vulnerable to CVE-2025-67038 (the EDS5000 series specifically is affected), the sheer number indicates a widespread deployment and a potentially large attack surface.
The geographic distribution is notable: a majority of exposed Lantronix devices are located in the United States, suggesting that U.S. organizations—including critical infrastructure operators, healthcare facilities, and manufacturers—are at elevated risk.
However, the true scope of vulnerable systems is likely underestimated by internet-facing device counts alone. Many organizations operate serial-to-IP converters on isolated or segmented networks, protecting them from direct external exploitation. Nevertheless, these internal systems remain vulnerable to:
## Recommendations for Organizations
Organizations dependent on serial-to-IP converters should prioritize the following actions:
### Immediate Actions (Within 48 Hours)
### Short-Term Mitigations (Within 1–2 Weeks)
### Long-Term Strategy
---
## HackWire Analysis
The timing of real-world exploitation—just two months after BRIDGE:BREAK went public—reflects a troubling pattern in OT security. Unlike software vulnerabilities that circulate in consumer and enterprise environments, industrial flaws often persist unpatched for years because OT systems prioritize availability and stability over rapid patching. When a researcher publicly demonstrates an industrial vulnerability, the window for opportunistic exploitation is brief but critical: adversaries rush to weaponize the flaw before defenders can even detect widespread exposure.
What makes CVE-2025-67038 particularly dangerous is that it targets a convergence point—the serial-to-IP bridge—that sits between legacy OT equipment and modern networks. These devices were often deployed before security best practices evolved, and they frequently lack update mechanisms entirely. An organization might have diligently patched its firewalls, endpoint protection, and cloud infrastructure while leaving a critical OT gateway completely undefended.
The healthcare implications deserve special attention. The Forescout researchers specifically demonstrated how sensor manipulation could conceal dangerous conditions in clinical environments. In June 2024, a hospital ransomware attack in Dallas forced emergency protocols when network compromise threatened patient care systems. A similar scenario triggered by a compromised serial-to-IP device—where monitoring systems report false normal readings while a patient deteriorates—could result in delayed intervention with catastrophic outcomes.
The federal mandate for federal agencies to patch by June 26 is a clear signal of urgency, but it applies only to government networks. Critical infrastructure operators in the private sector—hospitals, power utilities, water systems—have no such deadline. Many will likely not prioritize the vulnerability until a public breach report forces their hand.
The real story here is not the vulnerability itself, but the visibility gap: thousands of serial-to-IP devices are exposed on the internet, but most organizations don't know where theirs are or whether they're vulnerable. That asymmetry between attacker capability and defender awareness is exactly where exploitation thrives.
— HackWire Editorial
---
## Related Coverage