Critical

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

The Hacker News
Actively Exploited

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a serious vulnerability affecting Lantronix EDS5000 Series devices. This flaw, identified as CVE-2025-67038, has a high severity score of 9.8 and involves a code injection issue that could allow attackers to execute malicious code. CISA is urging Federal Civilian Executive Branch agencies to implement available fixes before the deadline of June 26, 2026. The active exploitation of this vulnerability raises concerns about potential unauthorized access and control over affected devices, which could lead to significant security breaches. Organizations using these devices should prioritize applying security updates to mitigate risks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Lantronix EDS5000 Series devices
  • Action Required: Federal Civilian Executive Branch agencies are advised to apply the available fixes by June 26, 2026.
  • Timeline: Newly disclosed

Original Article Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026. The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw that could result in the execution

Impact

Lantronix EDS5000 Series devices

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Federal Civilian Executive Branch agencies are advised to apply the available fixes by June 26, 2026.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

Ring adopts new TAKE encryption standard for smart home devices

SCM feed for Latest

Ring has adopted a new encryption standard called TAKE for its smart home devices. This standard uses a rotating set of encryption keys that are temporarily stored in the cloud, allowing Ring to secure active user features. The implementation of TAKE is designed to enhance the security of user data and improve the overall safety of smart home devices. While this development aims to bolster encryption practices, it raises questions about the security of cloud-stored keys and how they are managed. Users of Ring devices should stay informed about these changes to understand how their data is protected and what potential vulnerabilities may exist in the cloud storage approach.

Aug 26, 2026

Nimbus Manticore expands infrastructure and malware arsenal

SCM feed for Latest

Nimbus Manticore, linked to the Tortoiseshell hacking group, has expanded its capabilities by deploying a new SSH-based tunneling tool and a C++ backdoor that resembles its existing malware known as TWOSTROKE. This development indicates a shift in tactics, allowing attackers to establish more secure communications with compromised systems. The increase in their malware arsenal raises concerns for organizations that may be targeted, as it suggests a growing sophistication in their operations. Companies need to be vigilant and enhance their defenses against potential intrusions, especially those using SSH protocols. The implications of this escalation could lead to more successful breaches and data exfiltration if not addressed promptly.

Aug 26, 2026

Carhartt data breach claims inflated by synthetic data, analysis finds

SCM feed for Latest

On August 13, the hacking group ShinyHunters claimed to have leaked 50GB of data from Carhartt after demanding a ransom of $3.3 million. However, recent analysis suggests that the data leak may not be as significant as initially reported, with claims of inflated figures due to synthetic data. This incident raises concerns about the reliability of data breaches reported by cybercriminals and highlights the risks companies face from extortion attempts. If the data claims are exaggerated, it could lead to unnecessary panic among Carhartt's customers and stakeholders, as well as impact the company's reputation. It's crucial for organizations to remain vigilant and verify claims made by hackers to protect their interests.

Aug 26, 2026

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

CyberScoop

In response to ongoing cyber threats, President Trump signed an executive order aimed at protecting U.S. energy infrastructure from foreign-produced equipment that could pose national security risks. The order specifically prohibits the purchase and installation of such equipment, reflecting growing concerns over potential vulnerabilities in critical systems. This move targets equipment from foreign entities that may not adhere to U.S. security standards, highlighting the administration's focus on safeguarding essential infrastructure. The implications of this order could affect various energy projects and suppliers, especially those reliant on foreign technology. By tightening regulations on foreign equipment, the government aims to bolster national security and mitigate risks associated with cyber attacks.

Aug 26, 2026

Officials disrupt Chinese espionage operation that hit multiple federal agencies

CyberScoop

Authorities recently disrupted a Chinese espionage operation that had been infiltrating sensitive networks of multiple federal agencies for over eight years. The attackers, reportedly funded by the Chinese government, utilized a sophisticated hacking suite that enabled them to operate undetected for an extended period. The operation's exposure raises significant concerns about the security of federal systems and the potential for sensitive data breaches. This incident underscores the ongoing challenges that government agencies face in protecting their networks from foreign cyber threats. As investigations continue, the full scope of the damage and the specific agencies affected may become clearer.

Aug 26, 2026

Red Flags That Expose Fake North Korean IT Workers

darkreading

Researchers have identified that North Korean operatives are increasingly posing as IT workers to infiltrate organizations. These operatives have been refining their tactics, making them harder to detect. However, experts have pointed out several red flags that can help companies identify these fake IT workers before any harm is done. This situation is concerning as it highlights the potential for significant data breaches and cyberattacks against businesses that may unknowingly hire these individuals. Companies need to be vigilant and ensure they have robust vetting processes in place to protect themselves from these sophisticated threats.

Aug 26, 2026