Close Menu
    What's Hot

    Trump Clashes With Senate Republicans Over Iran in Heated Closed-Door Meeting

    Rutte Meets Trump Ahead of NATO Summit to Soothe Alliance Tensions

    OpenAI and Broadcom Unveil Custom A.I. Chip Design

    Facebook X (Twitter) Instagram
    Trending
    • Trump Clashes With Senate Republicans Over Iran in Heated Closed-Door Meeting
    • Rutte Meets Trump Ahead of NATO Summit to Soothe Alliance Tensions
    • OpenAI and Broadcom Unveil Custom A.I. Chip Design
    • Bitcoin hits 20-month low as market sentiment sours
    • Cerebras Systems Inc. (CBRS) Q1 2026 Earnings Call Transcript
    • Switzerland 2 – 1 Canada
    • Dozens died at Camp Mystic last summer. Now the Texas campground has filed for bankruptcy
    • Postmaster General Confirms Plan to Hold Back Mail Ballots Under Proposed Rule
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

    adminBy adminJune 24, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 24, 2026Vulnerability / Network Security

    CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026.

    The vulnerability in question is CVE-2025-67038 (CVSS score: 9.8), a code injection flaw that could result in the execution of arbitrary commands with elevated privileges.

    “The HTTP RPC module executes a shell command to write logs when the user’s authentication fails,” according to the vulnerability’s description on CVE.org. “The username is directly concatenated with the command without any sanitization. This allows attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.”

    The security flaw was disclosed by Forescout Research Vedere Labs in April 2026 as part of a broader set of vulnerabilities collectively codenamed BRIDGE:BREAK that impacted serial-to-IP converters from Lantronix and Silex. There are currently no details on how the vulnerability is being exploited, or who is making the effort.

    Cybersecurity

    The disclosure comes as CISA also confirmed active exploitation of three maximum-severity security defects in Ubiquity UniFi OS, days after Defused Cyber said it detected in-the-wild abuse of the remote code execution chain comprising CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to deploy commodity malware.

    • CVE-2026-34908 – An improper input validation vulnerability that could allow a malicious actor with access to the network to conduct command injection
    • CVE-2026-34909 – A path traversal vulnerability that could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
    • CVE-2026-34910 – An improper access control vulnerability that could allow a malicious actor with access to the network to make unauthorized changes to the system.
    Cybersecurity

    Earlier this month, Bishop Fox detailed a proof-of-concept (PoC) that chains together the three shortcomings to obtain a reverse shell with full root privileges in a single request. Patches for the flaws were released by Ubiquiti late last month.

    “The vulnerabilities could allow remote attackers to make unauthorized system changes, access sensitive files, disclose information, or execute arbitrary commands on vulnerable systems, highly impacting the confidentiality, integrity, and availability of targeted devices,” Belgium’s Centre for Cybersecurity said.

    “Given that UniFi OS devices are often centrally integrated into networks, successful compromise could enable lateral movement and broader network compromise.”

    Actively CISA critical EDS5000 Exploited flaw Lantronix warns
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleOpinion | 7 Lessons and Consequences of the Iran War
    Next Article I Met With China’s Top AI Experts. They’re Freaking Out, Too
    admin
    • Website

    Related Posts

    Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

    June 24, 2026

    Dawn of the Apex Agentic Adversary

    June 24, 2026

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    June 24, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Trump Clashes With Senate Republicans Over Iran in Heated Closed-Door Meeting

    Rutte Meets Trump Ahead of NATO Summit to Soothe Alliance Tensions

    OpenAI and Broadcom Unveil Custom A.I. Chip Design

    Bitcoin hits 20-month low as market sentiment sours

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by