
CVE-2025-67038 in Lantronix EDS5000 serial-to-IP converters is actively exploited in the wild. Forescout confirmed attackers reverse-engineered the firmware patch to build an exploit weeks before public disclosure. CISA added it to the KEV catalog June 23, 2026 with a 72-hour patch deadline.