CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation

A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation
Share

Key points

  • Active exploitation has been confirmed against CVE-2025-67038, a Lantronix serial-to-IP converter vulnerability carrying a 9.8 CVSS score.
  • The flaw was disclosed in April as part of the BRIDGE:BREAK research initiative, which targets vulnerabilities in devices that bridge legacy serial infrastructure to IP networks.
  • The gap between disclosure and exploitation is short, consistent with a pattern of threat actors monitoring the same research publications as defenders.
  • No threat cluster has been publicly attributed to this activity; opportunistic scanning remains the most defensible read at this stage.
  • Organizations running Lantronix hardware should patch, segment, or remove the device from exposure, and treat any gap in OT asset inventory as an equally urgent problem.

What is CVE-2025-67038 and why does it matter?

CVE-2025-67038 affects Lantronix serial-to-IP converters, devices that translate traffic from serial protocols such as MODBUS and DNP3 into TCP/IP, making them reachable from the network. A foothold on one can mean visibility into, or influence over, equipment that was never designed to be internet-adjacent. We covered the vulnerability and CISA's exploitation flag on 24 June 2026 in "CISA Flags Active Exploitation of Lantronix EDS5000 Code Injection Bug", where CISA gave federal agencies until 26 June to patch, a runway that already looked generous given confirmed in-the-wild activity.

Should you worry about the exploitation timeline?

The exploitation follows a pattern Threat Vectr has tracked in OT-adjacent disclosures: researchers flag a device class, defenders log the exposure, and threat actors move quickly on the same public information. Whether current exploitation reflects opportunistic scanning or targeted OT intrusion is not yet clear. Capability and intent are different things, and conflating them now would be premature.

No threat cluster attribution has been attached to this activity at time of writing. Groups with demonstrated OT interest, including Sandworm (tracked by Mandiant and ESET under various sub-cluster designations) and activity sets Dragos monitors in the industrial threat space, are worth watching given the device category. That is speculative framing, not attribution, medium confidence at best that this is anything beyond opportunistic exploitation of a freshly-publicized CVE.

What should defenders do now?

Consult the vendor advisory and cross-reference the NVD entry for CVE-2025-67038 for affected versions and remediation guidance.

Serial-to-IP converters are exactly the kind of asset that won't surface in a standard vulnerability scan. OT network edges remain systematically under-inventoried. If your team can't confirm whether Lantronix hardware is present in your environment, that's the first problem to solve, before patching becomes a meaningful option.

© 2026 Threat Vectr