CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CISA Warns Critical Lantronix EDS5000 Flaw CVE-2025-67038 Actively Exploited

June 25, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical vulnerability in Lantronix EDS5000 Series devices. The flaw, tracked as CVE-2025-67038 with a CVSS score of 9.8, is a code injection vulnerability that allows attackers to execute arbitrary commands with root privileges. The issue arises from the HTTP RPC module, which concatenates unsanitized usernames directly into shell commands during failed authentication attempts.

Disclosed by Forescout Research Vedere Labs in April 2026 as part of the BRIDGE:BREAK vulnerability set, the flaw impacts serial-to-IP converters from Lantronix and Silex. CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply patches by June 26, 2026. No details on exploitation methods or threat actors have been released.

In related news, CISA also confirmed active exploitation of three maximum-severity vulnerabilities in Ubiquiti UniFi OS (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910). These flaws, disclosed by Defused Cyber, enable remote code execution and have been used to deploy commodity malware. Patches were released by Ubiquiti in late May 2026. Belgium’s Centre for Cybersecurity warned that successful compromise could facilitate lateral movement within networks.

CVEs: CVE-2025-67038, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-11645

Companies: Lantronix, Forescout Research Vedere Labs, Ubiquiti, Defused Cyber, Bishop Fox, Centre for Cybersecurity Belgium

Products: Lantronix EDS5000 Series, Ubiquiti UniFi OS