Security · 2h ago
CISA Warns Critical Lantronix EDS5000 Flaw Actively Exploited
CISA warned of active exploitation of CVE-2025-67038, a critical code injection flaw in Lantronix EDS5000 devices with a CVSS score of 9.8. Federal agencies must patch by June 26, 2026. The vulnerability could allow remote code execution without authentication.
Meridian48 take
This is a high-severity, actively exploited vulnerability in industrial networking gear, underscoring the ongoing risk to critical infrastructure from unpatched OT devices.
Read the full reporting
CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited →
The Hacker News
cisa-warninglantronix-eds5000