HomeSecurityCISA: Lantronix and Ubiquity vulnerabilities in the KEV List

CISA: Lantronix and Ubiquity vulnerabilities in the KEV List

The U.S. Cybersecurity and Infrastructure Security Administration(CISA) has issued a warning about active exploitation of a critical security vulnerability affecting Lantronix EDS5000 series devices. CISA has called on federal agencies (FCEB) to implement the necessary fixes by June 26, 2026, underscoring the seriousness of the situation.

CISA Lantronix and Ubiquity Vulnerabilities

CISA: Lantronix vulnerability

The vulnerability, known as CVE-2025-67038, has a CVSS score of 9.8, indicating its high risk. It is a vulnerability code injection that can lead to the execution of arbitrary commands with elevated privileges. Its description on CVE.org states that the HTTP RPC module executes a shell command to write , when user authentication fails. The username is directly attached to the command without sanitization, thus allowing attackers to inject arbitrary operating system commands in the username parameter. At the same time, the injected commands are executed with root privileges, making the vulnerability extremely dangerous.

See also: CISA warns of vulnerability in Libraesva ESG

The vulnerability was first disclosed by Forescout Research Vedere Labs in April 2026, as part of a larger set of vulnerabilities collectively codenamed BRIDGE:BREAK. These vulnerabilities affected serial-to-IP converters from Lantronix and Silex. Despite the disclosure, there are still no details on how the vulnerability is being exploited or who is behind the attacks, raising concerns about the potential consequences.

Lantronix EDS5000 - SecNews.gr

CISA: Ubiquity Vulnerabilities

The CISA warning comes at a time when cybersecurity is in the spotlight, as three maximum severity vulnerabilities in Ubiquity UniFi OS have also been confirmed to be actively exploited. These vulnerabilities, listed as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, were discovered by Defused Cyber, which detected the exploitation of the vulnerability chain to develop common malware.

See also: CISA warns of 5 vulnerabilities that are being actively exploited

CVE -2026-34908 is an “ improper input validation ” vulnerability, which allows a malicious user with network access to conduct command injection . CVE-2026-34909 is a “ path traversal ” vulnerability, which allows access to files on the underlying system, while CVE-2026-34910 is an improper access control vulnerability , which allows unauthorized changes to the system.

Bishop Fox presented a PoC exploit that combines these three vulnerabilities to obtain a reverse shell with full root privileges in a single request.

Patches for the vulnerabilities were released by Ubiquiti late last month, but the existence of these vulnerabilities highlights the need for continued vigilance and prompt application of security updates.

CISA: Lantronix and Ubiquity vulnerabilities in the KEV List

The implications of these vulnerabilities are serious. Attackers could exploit these weaknesses to make unauthorized changes to the system, gain access to sensitive files, disclose information, or execute arbitrary commands on vulnerable systems. This could significantly impact the confidentiality, integrity, and availability of targeted devices.

See also: CISA warns about FortiBleed – 86,644 FortiGate devices compromised

In particular, UniFi OS devices , which are often centrally integrated into networks, are a critical security hotspot. Successful compromise of these devices could allow lateral movement and broader network compromise , making immediate patching imperative to protect systems.

This situation highlights the importance of continuous monitoring and prompt response to cybersecurity threats. Organizations must ensure that their devices are up-to-date and protected, while users must be aware of potential threats and take the necessary measures to protect their data. Collaboration between government agencies, companies and research organizations is critical to addressing the growing challenges in the field of cybersecurity.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS