A vulnerability that can facilitate attacks on operational technology (OT) systems is being exploited in the wild, according to the cybersecurity agency CISA.
The vulnerability is tracked as CVE-2025-67038 and it affects Lantronix EDS5000 serial-to-IP device servers, which enable organizations to remotely connect to and manage their serial devices.
The flaw can be exploited by an unauthenticated attacker to inject arbitrary OS commands into a username parameter, which leads to the execution of the commands with root privileges.
SecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary Edition
CVE-2025-67038 was one of the 20 serial-to-IP product vulnerabilities disclosed by cybersecurity firm Forescout in April.







