Briefing

CISA Issues Patch Alert for Ubiquiti and Lantronix Vulnerabilities

security
by [email protected] (The Hacker News) · deadline 26 Jun 2026 · CVE-2025-67038

Apply the Lantronix EDS5000 firmware patch before 26 June 2026 to mitigate the code injection flaw.

What to do now

Apply the Lantronix EDS5000 firmware patch to all devices by 26 June 2026.

Summary

On 24 June 2026 the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released Board of Directors Order 26‑04, demanding that federal agencies apply security updates or mitigations for four high‑severity vulnerabilities that are being actively exploited. The flaws affect Ubiquiti’s UniFi OS and Lantronix’s serial‑to‑ethernet servers. CVE‑2026‑34908 is an access‑control bypass that lets unauthenticated attackers modify device settings; CVE‑2026‑34909 is a directory traversal flaw that exposes sensitive files; CVE‑2026‑34910 allows arbitrary OS command injection; and CVE‑2025‑67038 is a root‑level command injection in Lantronix EDS5000 firmware 2.1.0.0R3. All four vulnerabilities enable remote code execution without requiring privileged access.

Ubiquiti released patches for the three UniFi OS flaws in May, and Lantronix issued an update that upgrades the EDS5000 to firmware 2.2.0.0R1. Security researchers at Bishop Fox demonstrated that the three UniFi OS flaws can be chained to achieve full remote code execution with elevated privileges, and they published a free detection script on GitHub. Although CISA has not confirmed active exploitation of any of the four flaws, the agency’s advisory flagged the “use in ransomware campaigns” status as “Unknown” for all of them, underscoring the potential for malicious use. The directive requires agencies to apply the available updates or mitigations within three days, highlighting the critical importance of timely patching for network infrastructure devices.

The advisory has prompted system administrators across federal agencies to prioritize the installation of the latest firmware and to monitor their networks for signs of exploitation. By drawing attention to the active exploitation of these vulnerabilities, CISA aims to prevent potential ransomware attacks and other malicious activities that could compromise sensitive data and disrupt critical services. The incident serves as a reminder of the ongoing threat landscape faced by network equipment vendors and the necessity for rapid response to newly discovered security flaws.

Key changes

  • CVE-2025-67038 in Lantronix EDS5000 Series devices
  • CVSS score 9.8, code injection flaw
  • Active exploitation reported by CISA
  • Affects federal civilian executive branch agencies
  • Fix required by 26 June 2026
  • Vulnerability could allow arbitrary code execution

Affects

none

Source angles · 2 perspectives

The Hacker News
Independent angle

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

Open
Bleeping Computer
Independent angle

CISA warns of max severity Ubiquiti flaws exploited in attacks

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting