Home / Jun 26, 2026 / Story
0
#5 The Hacker News general June 24, 2026 at 17:19 UTC

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

By [email protected] (The Hacker News)

AI Summary

CISA issued an urgent warning on June 24 that CVE-2025-67038 (CVSS 9.8), a critical code injection flaw in Lantronix EDS5000 Series serial-to-IP converter devices, is being actively exploited in the wild. FCEB agencies were ordered to apply fixes by June 26, 2026, the same day the vulnerability was flagged by SecurityWeek as part of the April 2026 BRIDGE:BREAK OT research disclosure. The flaw is particularly concerning given Lantronix devices' prevalence in industrial and OT network environments bridging legacy serial equipment to IP networks.

Relevance score: 82.0/100

# More from June 26