Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

    June 25, 2026

    DoorDash Delivery Robot Invades SWAT Scene, Won’t Leave as Cops Flashbang Resident

    June 25, 2026

    Play Zenless Zone Zero and Fortnite

    June 25, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
    Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
    Cybersecurity

    Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

    The Tech GuyBy The Tech GuyJune 25, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A vulnerability that can facilitate attacks on operational technology (OT) systems is being exploited in the wild, according to the cybersecurity agency CISA.

    Advertisement

    The vulnerability is tracked as CVE-2025-67038 and it affects Lantronix EDS5000 serial-to-IP device servers, which enable organizations to remotely connect to and manage their serial devices.

    The flaw can be exploited by an unauthenticated attacker to inject arbitrary OS commands into a username parameter, which leads to the execution of the commands with root privileges.

    SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition

    CVE-2025-67038 was one of the 20 serial-to-IP product vulnerabilities disclosed by cybersecurity firm Forescout in April. 

    Collectively tracked as BRIDGE:BREAK, the vulnerabilities impact Lantronix and Silex products, and researchers demonstrated how they can be exploited to manipulate sensor readings in industrial and healthcare environments to conceal dangerous conditions that would normally require human intervention, or to cause disruption in a healthcare environment using malicious firmware.

    Advertisement. Scroll to continue reading.

    CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog on June 23, instructing federal agencies to address it by June 26. 

    However, there do not appear to be any public reports describing the attacks exploiting the Lantronix product vulnerability. It’s unclear if the attacks are aimed at industrial, healthcare, or other OT environments.

    Cybersecurity firm Aviatrix has described a potential attack scenario involving CVE-2025-67038. Once the attacker exploits the vulnerability to execute code with root privileges, they can gain full control of the device.

    “The compromised device serves as a foothold for the attacker to move laterally within the network, targeting other connected systems. The attacker establishes a command and control channel to remotely manage the compromised device and issue further commands,” Aviatrix explained in an advisory.

    It added, “Sensitive data is exfiltrated from the network through the compromised device. The attacker disrupts network operations by modifying configurations or deploying malware, causing significant impact to the organization’s infrastructure.”

    ZoomEye shows thousands of internet-exposed Lantronix systems — a majority in the United States — but these include all Lantronix products and it’s unclear how many of them are vulnerable to attacks. 

    Lantronix has not responded to SecurityWeek’s request for comment regarding in-the-wild exploitation.

    Related: Critical HVAC and UPS Vulnerabilities Could Let Hackers Disrupt Data Centers

    Related: Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software

    Related: Dragos Unveils AI for OT Security

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Exclusive: Meet AIVEX, a New Triage Model Built to Reduce Supply Chain Threat and Risk

    June 25, 2026

    When Information Becomes the Attack Surface – Understanding AI Agent Traps

    June 24, 2026

    Microsoft and Allies Smash Shared Infrastructure of Amadey and StealC Malware

    June 24, 2026

    Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

    June 24, 2026

    Anthropic’s Mythos Model Found Vulnerabilities in Classified US Government Systems, Official Says

    June 24, 2026

    Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

    June 23, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202684 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 202621 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning

    June 25, 2026

    DoorDash Delivery Robot Invades SWAT Scene, Won’t Leave as Cops Flashbang Resident

    June 25, 2026

    Play Zenless Zone Zero and Fortnite

    June 25, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.