CVE-2025-67038: Lantronix Serial-to-IP Flaw Moves From Research to Active Exploitation
A vulnerability disclosed through the BRIDGE:BREAK project is now seeing exploitation in the wild, raising fresh concerns about attacker interest in operational technology network edges.

Active exploitation has been confirmed against CVE-2025-67038, a vulnerability affecting Lantronix serial-to-IP converters. The flaw was disclosed in April as part of the BRIDGE:BREAK research initiative — a project targeting vulnerabilities in devices that bridge legacy serial infrastructure to IP networks.
These converters sit at a quiet but consequential seam in OT environments. They translate traffic from serial protocols — MODBUS, DNP3, proprietary industrial formats — into TCP/IP. That makes them reachable from the network. It also means a foothold on one can mean visibility into, or control over, equipment that was never designed to be internet-adjacent.
The gap between disclosure and exploitation here is short. That alone warrants attention.
BRIDGE:BREAK surfaced the issue alongside a broader OT threat warning, which tracks with a wider pattern: researchers flag a device class, defenders note the exposure, and threat actors — apparently monitoring the same research — move quickly. Whether the current exploitation reflects opportunistic scanning or targeted OT intrusion is not yet clear. Capability and intent are different things, and conflating them at this stage would be premature.
No threat cluster attribution has been publicly attached to this activity at time of writing. Given the device category, the target set worth watching includes groups with demonstrated OT interest: Sandworm (tracked by Mandiant and ESET under various sub-cluster designations), and activity sets overlapping with what Dragos tracks in the industrial threat space. That's speculative framing, not attribution — medium confidence at best that this is anything beyond opportunistic exploitation of a freshly-publicized CVE.
Organizations running Lantronix devices should consult the vendor's advisory and cross-reference the NVD entry for CVE-2025-67038 for affected versions and remediation guidance. Patch, segment, or pull the device from exposure — in that priority order.
OT network edges remain systematically under-inventoried. Serial-to-IP converters are exactly the kind of asset that doesn't show up in a standard vulnerability scan. If your team doesn't know whether Lantronix hardware is in your environment, that's the first problem to solve.



