Back to all lessons
Awareness Lessons
4 months ago

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog

Four vulnerabilities across Lantronix EDS5000 and Ubiquiti UniFi OS devices have been added to CISA's Known Exploited Vulnerabilities Catalog due to confirmed active exploitation in the wild. The flaws span critical vulnerability classes including code injection, improper access control, path traversal, and input validation failures — all of which can allow attackers to gain unauthorized access or execute arbitrary code on affected network appliances. Federal agencies are legally required under BOD 26-04 to prioritize remediation of KEV-listed vulnerabilities on internet-exposed assets, but the risk extends equally to private sector organizations running the same equipment. Delaying patches on network-edge devices significantly increases exposure, as these systems are often directly reachable from the internet and serve as entry points into internal infrastructure.

Tactical Insight

Immediate Actions

  • Apply available vendor patches for CVE-2025-67038 (Lantronix EDS5000) and all three Ubiquiti UniFi OS CVEs immediately on any internet-facing deployments.
  • Run an authenticated vulnerability scan across all network appliances to identify unpatched instances of affected firmware versions.

Long-Term Improvements

  • Maintain a continuously updated asset inventory of all network appliances, IoT devices, and edge hardware to ensure no device is overlooked during patch cycles.
  • Establish a formal emergency patching SLA (e.g., 24–72 hours) specifically for KEV-listed vulnerabilities on publicly exposed assets.
  • Subscribe to CISA KEV Catalog feeds and integrate them into your vulnerability management platform to automate prioritization.

Detection & Containment Measures

  • Implement network segmentation to isolate management interfaces of Lantronix and Ubiquiti devices from general user traffic and the public internet.
  • Enable logging and behavioral monitoring on network appliances to detect anomalous access patterns indicative of path traversal or injection exploitation attempts.