22 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP Converters
22 BRIDGE:BREAK flaws expose 20,000 Lantronix and Silex serial-to-IP converters, enabling device hijacking.
Run Lantronix?
Get an email when a reviewed story names Lantronix, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Researchers discovered 22 vulnerabilities, dubbed BRIDGE:BREAK, in Lantronix and Silex serial-to-IP converters. Successful exploitation could allow attackers to disrupt serial communications, conduct lateral movement, and tamper with sensor values. Patches are available, and users are advised to implement network segmentation and avoid exposing the devices to the internet.
Full text
22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters Ravie LakshmananApr 21, 2026Network Security / Vulnerability Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged by them. The vulnerabilities have been collectively codenamed BRIDGE:BREAK by Forescout Research Vedere Labs, which identified nearly 20,000 Serial-to-Ethernet converters exposed online globally. "Some of these vulnerabilities allow attackers to take full control of mission-critical devices connected via serial links," the cybersecurity company said in a report shared with The Hacker News. Serial-to-IP converters are hardware devices that enable users to remotely access, control, and manage any serial device over an IP network or the internet by "bridging" legacy applications and industrial control systems (ICS) that operate over TCP/IP. At a high level, as many as eight security flaws have been discovered in Lantronix products (EDS3000PS Series and EDS5000 Series) and 14 in Silex SD330-AC. These shortcomings fall under the following broad categories - Remote code execution - CVE-2026-32955, CVE-2026-32956, CVE-2026-32961, CVE-2025-67041, CVE-2025-67034, CVE-2025-67035, CVE-2025-67036, CVE-2025-67037, and CVE-2025-67038 Client-side code execution - CVE-2026-32963 Denial-of-service (DoS) - CVE-2026-32961, CVE-2015-5621, CVE-2024-24487 Authentication bypass - CVE-2026-32960, CVE-2025-67039 Device takeover - FSCT-2025-0021 (no CVE assigned), CVE-2026-32965, CVE-2025-70082 Firmware tampering - CVE-2026-32958 Configuration tampering - CVE-2026-32962, CVE-2026-32964 Information disclosure - CVE-2026-32959 Arbitrary file upload - CVE-2026-32957 Successful exploitation of the aforementioned flaws could allow attackers to disrupt serial communications with field assets, conduct lateral movement, and tamper with sensor values or modify actuator behavior. In a hypothetical attack scenario, a threat actor could gain initial access to a remote facility through an internet-exposed edge device, such as an industrial router or firewall, and then weaponize BRIDGE:BREAK vulnerabilities to compromise the serial-to-IP converter, and alter serial data moving to or from the IP network. Lantronix and Silex have released security updates to address the identified issues - Lantronix EDS3000PS Series Lantronix EDS5000 Series Silex Besides applying patches, users are advised to replace default credentials, avoid using weak passwords, segment networks to prevent bad actors from reaching vulnerable serial-to-IP converters or using them as jumping-off points to other critical assets, and ensure the devices are not exposed to the internet. "This research highlights weaknesses in serial-to-IP converters and the risks they can introduce in critical environments," Forescout said. "As these devices are increasingly deployed to connect legacy serial equipment to IP networks, vendors and end-users should treat their security implications as a core operational requirement." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE cybersecurity, Firmware Security, industrial control system, network security, remote code execution, Vulnerability ⚡ Top Stories This Week Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories Microsoft Warns of Two Actively Exploited Defender Vulnerabilities 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective The New Phishing Click: How OAuth Consent Bypasses MFA Developer Workstations Are Now Part of the Software Supply Chain ⭐ Featured Resources Claim ANY.RUN Anniversary Offer for Faster Malware Analysis [Guide] Learn to Detect AI Typosquatting Risks in Your Domain [Guide] Get Key Identity Security Insights From 2026 Snapshot Discover How to Navigate the Era of Constant Cyber Exposure
Indicators of Compromise
- cve — CVE-2026-32955
- cve — CVE-2026-32956
- cve — CVE-2026-32961
- cve — CVE-2025-67041
- cve — CVE-2025-67034
- cve — CVE-2025-67035
- cve — CVE-2025-67036
- cve — CVE-2025-67037
- cve — CVE-2025-67038
- cve — CVE-2026-32963
- cve — CVE-2015-5621
- cve — CVE-2024-24487
- cve — CVE-2026-32960
- cve — CVE-2025-67039
- cve — CVE-2026-32965
- cve — CVE-2025-70082
- cve — CVE-2026-32958
- cve — CVE-2026-32962
- cve — CVE-2026-32964
- cve — CVE-2026-32959
- cve — CVE-2026-32957