Critical vulnerabilities in Lantronix EDS5000 and Unifi OS that allow you to run commands like root and take full control

Author: Published 4 min de lectura 150 reading

The images in this article were generated with artificial intelligence. How we publish

The American Agency CISA has ignited an alarm that should be taken seriously: there are active holdings against critical vulnerability in the series-a-IP Lantronix EDS5000 converters (CVE-2025-67038) and, at the same time, abuses in the remote execution chain affecting Ubiquiti's Unifi OS (CVE-2026-34908 / 34909 / 34910) have also been confirmed. The first failure allows the injection of commands through the user name parameter in the HTTP RPC module and, according to the public description, the injected commands are run with root privileges, which makes any access to that service a direct door for total device commitments.

This type of defect is not just technical discomfort: with a CVSS score of 9.8 in the case of Lantronix and similar in UniFi OS, we talk about vectors that can serve as a trampoline for lateral movement, exfiltration of data or installation of persistent back doors on business networks. The initial research that christened a set of failures in serial-to-IP converters like BRIDGE: BREAK, published by research teams such as Forecout Vedere Labs, shows that these devices - often forgotten in inventories - are embedded in critical production and control infrastructures that require less operational attention but involve high operational risk if they are compromised. More technical information and research notes can be found in the research repository of Forescout: Forecout Research.

Critical vulnerabilities in Lantronix EDS5000 and Unifi OS that allow you to run commands like root and take full control
Image generated with IA.

For its part, reported incidents of Unifi OS have escalated because there is a concept test that links three failures to achieve a reverse shell with root privileges in a single request, something detailed by researchers like Bishop Fox. That capacity means that an attacker with access to the network can, without additional intervention, take absolute control of the device and pivote into other systems on the same network. Bishop Fox explains techniques and PoC in his technical blog, which is useful to understand the operating mechanism: Bishop Fox Blog.

The immediate and priority response is clear: to implement the official patches. CISA has urged the civil federal agencies to install the corrections for the EDS5000 before 26 June 2026, and Ubiquiti already published updates for the UniFi OS variants. However, in real operating environments the application of firmware and patches is not always trivial: it requires planning, maintenance windows and compatibility tests. Such planning should include validation that the updates remove the exposure points (e.g. disabling the HTTP RPC module if not necessary) and post-patch verification through scans and regression tests.

If it is not possible to park immediately, there are mitigating measures that must be implemented without delay. It should isolate vulnerable devices behind network segmentation, access control lists and filters that limit access to the port and services affected from unreliable subnetworks or the Internet. Block HTTP / RPC access from external networks, apply edge firewalls and rules on IDS / IPS to detect command injection patterns can gain time while permanent solutions are deployed. In addition, a comprehensive inventory is essential: many environments do not even know how many series-to-IP converters or UniFi gateways have assets in their infrastructure.

Critical vulnerabilities in Lantronix EDS5000 and Unifi OS that allow you to run commands like root and take full control
Image generated with IA.

Incident management should assume the possibility of prior commitment: to review logs, to search for compromise indicators (IOCs) related to atypical communications, suspected binary or modified accounts, and to apply containment controls such as stealing sessions, revoking credentials and, if necessary, rebuilding devices affected from clean images. For organisations operating critical infrastructure or industrial chains, the most prudent policy is to disconnect unsafe devices from control networks to confirm their integrity or have referred them to a controlled mediation procedure.

No less important is governance: these vulnerabilities underline the need for procurement and maintenance policies that require security updates, life cycle support and response contracts with suppliers. IT and OT teams should coordinate inventories, tests and deployments, and maintain priority lists of critical assets. It is also recommended to subscribe to official warning sources and security bulletins - for example, the CISA page for warnings and alerts - to receive early notifications: CISA Alerts.

Finally, the broader lesson is operational and cultural: infrastructure devices that are traditionally considered "peripheral" now represent central risk vectors. The combination of active holdings, public PoC and recent patches requires security teams to act quickly but with method. Implementing patches, segmenting networks, auditing inventories and preparing response plans are not options: they are requirements to minimize the impact of vulnerabilities such as CVE-2025-67038 and the CVE-2026-34908 / 34909 / 34910 series in Unifi OS.

Coverage

Related

More news on the same subject.