CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug

CVE-2025-67038 carries a 9.8 CVSS. Federal agencies have until June 26, 2026 to patch — but if it's already being hit in the wild, that runway looks generous.

ThreatVectr Newsdesk· 2 min read
CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug
Share

CISA has added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog, citing active exploitation against Lantronix EDS5000 Series device servers.

The bug is a code injection flaw. CVSS 9.8. Successful exploitation can lead to arbitrary code execution on the affected device — which, given what EDS5000 hardware actually does, is the part defenders should sit with.

These are serial-to-Ethernet device servers. They sit between IP networks and legacy serial endpoints in industrial, medical, and building-automation environments. Compromise one and you're not just on the box; you're typically adjacent to whatever PLC, sensor, or controller it was fronting.

CISA's directive gives Federal Civilian Executive Branch agencies until June 26, 2026 to remediate under BOD 22-01. That's the standard catalog timeline. It is not a statement about how much time you actually have before someone scans your edge.

The agency did not publish indicators of compromise or attribution in its initial listing (KEV entries rarely do). No public PoC has been linked at the time of writing, though code injection bugs in embedded HTTP management interfaces tend not to stay private for long once they hit KEV.

What to do now:

  • Inventory any Lantronix EDS5000 Series units on your network, including units deployed by OT or facilities teams that may not appear in IT asset systems.
  • Apply Lantronix's fixed firmware once confirmed against the vendor's advisory, and pull management interfaces off any network segment reachable from the internet or general corporate VLANs.

If you can't patch immediately, the usual containment applies: ACL the management plane to a jump host, log all access, and watch for anomalous outbound connections from the device itself. EDS-class boxes shouldn't be initiating much traffic of their own.

A few caveats worth flagging. CISA's KEV entry confirms exploitation but does not specify scope, threat actor, or whether the activity is opportunistic scanning versus targeted intrusion. The 9.8 score assumes network-reachable, unauthenticated exploitation — if your devices are properly segmented, your real-world exposure is lower (though "properly segmented" is doing heavy lifting in most environments I've seen).

This is the second time in recent memory that a serial-to-IP gateway has shown up on KEV. These devices age in place. They get installed during a building retrofit and then nobody touches them for eight years. Treat the patch cycle accordingly: assume yours is unmanaged until you prove otherwise.

Lantronix has not, as of this writing, published a public post-mortem naming the reporter. We'll update if that changes.

© 2026 Threat Vectr