ctipilot.ch

Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23)

cve · CVE-2025-67038

Coverage timeline
2
first 2026-06-24 → last 2026-06-29
Peak priority
notable
2 notable
Sources cited
2
2 hosts
Sections touched
2
trending-vulnerabilities, weekly-vuln-rollup
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.1 · see below

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-24/cve-2025-67038-lantronix-eds5000-serial-to-ip-converter-unau · ATT&CK page ↗

Story timeline

  1. 2026-06-29CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)
    weekly-vuln-rollup
  2. 2026-06-24CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1
  • weekly-vuln-rollup1

Source distribution

  • forescout.com1 (50%)
  • securityweek.com1 (50%)

Entries about Lantronix EDS5000 OS command injection to root (BRIDGE:BREAK; CISA KEV 2026-06-23) (2)

2026-06-29 · view entry permalink →

NOTABLECVE-2025-67038exploited

CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)

Forescout Vedere Labs' BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call. The in-window development is its CISA KEV listing on 2026-06-23 with confirmed in-the-wild exploitation (covered in daily 06-24) — the first BRIDGE:BREAK flaw to flip from research to active abuse. Serial-to-IP converters sit in front of OT, building-management and medical serial devices; firmware 2.0.0R1 closes it. This is an energy/water/healthcare exposure, not an IT one.

Forescout Vedere Labs' BRIDGE:BREAK research documented an unauthenticated OS command-injection flaw in Lantronix EDS5000-series device servers — the HTTP management interface concatenates unsanitised input into a shell call.

ctipilot v2 brief (migrated)
vulnerability29 Jun 00:21Zmulti-sourceOpen finding ↗

2026-06-24 · view entry permalink →

NOTABLECVE-2025-67038exploited

CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV

CVE-2025-67038 (CVSS 9.8) is an OS command-injection flaw in the Lantronix EDS5000-series serial-to-IP device servers (EDS5008/5016/5032): the HTTP management interface concatenates an unsanitised request parameter into a shell command, letting an unauthenticated remote attacker execute commands as root. It is one of the 22 vulnerabilities Forescout Vedere Labs disclosed in April 2026 as BRIDGE:BREAK, covering Lantronix and Silex serial-to-Ethernet converters (Forescout Vedere Labs, 2026-04-21; SecurityWeek, 2026-04-20). CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog on 2026-06-23 — the first confirmed in-the-wild exploitation of any BRIDGE:BREAK CVE, which makes it a priority for any operator who deferred the April advisory. EDS5000 units bridge legacy serial OT/ICS equipment (PLCs, relays, meters) onto IP networks, so a compromise yields a foothold adjacent to field devices, not just the converter. Forescout's disclosure cites fixed firmware 2.0.0R1 for the EDS5000 series; because the KEV-era advisory references later builds (, confirm the running firmware against Lantronix's current advisory rather than a single version number. Maps to T1190 (Exploit Public-Facing Application). Mitigations: patch to the current EDS5000 firmware, replace default credentials, and segment serial-to-IP converters off any internet-reachable or flat OT segment; hunt management-interface auth logs for shell metacharacters in request fields and unexpected scans of TCP/80/443 on these devices.

The vulnerabilities, collectively tracked as BRIDGE:BREAK, can be exploited for OS command injection and remote code execution, firmware tampering, denial-of-service (DoS) attacks, and device takeovers.

SecurityWeek

Lantronix has released two firmware updates that address the issues: 2.0.0R1 for EDS5000 series

Forescout Vedere Labs
vulnerability24 Jun 05:11Zmulti-sourceOpen finding ↗