CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug

CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch, but if it's already being hit in the wild, that runway looks generous.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug
Share

Key points

  • CISA has added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog, confirming active exploitation.
  • The flaw is a code injection bug scoring 9.8 on the CVSS scale, meaning network-reachable, unauthenticated exploitation is the assumed scenario.
  • Affected hardware, the Lantronix EDS5000 Series, bridges IP networks to legacy serial endpoints in industrial and building-automation environments.
  • Federal Civilian Executive Branch agencies must remediate by June 26, 2026.
  • No indicators of compromise or attacker attribution appear in CISA's initial listing.

CISA has added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog, citing active exploitation against Lantronix EDS5000 Series device servers.

The bug is a code injection flaw. CVSS 9.8. Successful exploitation can lead to arbitrary code execution on the affected device, which, given what EDS5000 hardware actually does, is the part defenders should sit with.

These are serial-to-Ethernet device servers. They sit between IP networks and legacy serial endpoints in industrial and building-automation environments. Compromise one and you're not just on the box; you're typically adjacent to whatever PLC or controller it was fronting.

Should you wait for the federal deadline?

The June 26, 2026 remediation date applies to Federal Civilian Executive Branch agencies. It's not a statement about how much time you actually have before someone scans your edge. Code injection bugs in embedded HTTP management interfaces tend not to stay private for long once they land in KEV, a pattern we've tracked across recent additions including the Oracle WebLogic flaw from 2 June.

CISA did not publish indicators of compromise or attribution in its initial listing. No public proof-of-concept has been linked at the time of writing.

What should you do right now?

Inventory any Lantronix EDS5000 Series units on your network, including units deployed by OT or facilities teams that may not appear in IT asset systems. Apply Lantronix's fixed firmware once confirmed against the vendor's advisory, and pull management interfaces off any network segment reachable from the internet or general corporate VLANs.

If you can't patch immediately: restrict management-plane access to a jump host, log everything, and watch for anomalous outbound connections from the device itself. EDS-class boxes shouldn't be initiating much traffic of their own.

How worried should you be about your segmentation?

The 9.8 score assumes network-reachable, unauthenticated exploitation. If your devices are properly segmented, real-world exposure is lower, though "properly segmented" is doing heavy lifting in most environments I've seen.

CISA's entry confirms exploitation but does not specify scope or whether the activity is opportunistic scanning versus targeted intrusion. Those are different threat models, and the catalog doesn't help you choose between them.

These devices age in place. They get installed during a building retrofit and then nobody touches them for years. Treat the patch cycle accordingly: assume yours is unmanaged until you prove otherwise.

Lantronix has not, as of this writing, published a public post-mortem naming the reporter. We'll update if that changes.

© 2026 Threat Vectr