---
schema: 1
kind: vulnerability
title: "CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV"
headline: "CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV"
summary: "CVE-2025-67038 (CVSS 9.8) is an OS command-injection flaw in the Lantronix EDS5000-series serial-to-IP device servers (EDS5008/5016/5032): the HTTP management interface concatenates an unsanitised request parameter into a shell command, letting an unauthenticated remote attacker execute commands as root."
discovered_at: "2026-06-24T05:11:50Z"
event_date: 2026-04-21
run_id: 2026-06-24-de656486
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - actively-exploited
  - cisa-kev
  - pre-auth
  - rce
  - ot-ics
  - patch-available
regions:
  - global
  - europe
sectors:
  - energy
  - manufacturing
  - water
entities: []
cves:
  - id: CVE-2025-67038
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/"
    publisher: "Forescout Vedere Labs — BRIDGE:BREAK"
    role: primary
  - url: "https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/"
    publisher: SecurityWeek
    role: corroborating
closed_sources: []
evidence:
  - quote: "The vulnerabilities, collectively tracked as BRIDGE:BREAK, can be exploited for OS command injection and remote code execution, firmware tampering, denial-of-service (DoS) attacks, and device takeovers."
    publisher: SecurityWeek
  - quote: "Lantronix has released two firmware updates that address the issues: 2.0.0R1 for EDS5000 series"
    publisher: Forescout Vedere Labs
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-24.md
---

**CVE-2025-67038** (CVSS 9.8) is an OS command-injection flaw in the Lantronix EDS5000-series serial-to-IP device servers (EDS5008/5016/5032): the HTTP management interface concatenates an unsanitised request parameter into a shell command, letting an unauthenticated remote attacker execute commands as root. It is one of the 22 vulnerabilities Forescout Vedere Labs disclosed in April 2026 as **BRIDGE:BREAK**, covering Lantronix and Silex serial-to-Ethernet converters ([Forescout Vedere Labs, 2026-04-21](https://www.forescout.com/blog/exploiting-serial-to-ethernet-converters-in-critical-infrastructure/); [SecurityWeek, 2026-04-20](https://www.securityweek.com/serial-to-ip-converter-flaws-expose-ot-and-healthcare-systems-to-hacking/)). CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog on 2026-06-23 — the first confirmed in-the-wild exploitation of any BRIDGE:BREAK CVE, which makes it a priority for any operator who deferred the April advisory. EDS5000 units bridge legacy serial OT/ICS equipment (PLCs, relays, meters) onto IP networks, so a compromise yields a foothold adjacent to field devices, not just the converter. Forescout's disclosure cites fixed firmware **2.0.0R1** for the EDS5000 series; because the KEV-era advisory references later builds (, confirm the running firmware against Lantronix's current advisory rather than a single version number. Maps to `T1190` (Exploit Public-Facing Application). Mitigations: patch to the current EDS5000 firmware, replace default credentials, and segment serial-to-IP converters off any internet-reachable or flat OT segment; hunt management-interface auth logs for shell metacharacters in request fields and unexpected scans of TCP/80/443 on these devices.
