Businesswire New Vulnerabilities Discovered in Serial-to-IP Converters Threaten Critical Infrastructure
Article Content
- •Forescout identified 22 new vulnerabilities in serial-to-IP converters from Lantronix and Silex.
- •These vulnerabilities can be exploited without authentication, posing severe risks to critical infrastructure.
- •CISA has warned operators to strengthen cybersecurity measures following a related cyberattack on Poland's energy grid.
Forescout Technologies has identified 22 new vulnerabilities in serial-to-IP converters from Lantronix and Silex, which are widely used in critical sectors like healthcare and utilities. These vulnerabilities, collectively known as BRIDGE:BREAK, can be exploited without authentication, allowing attackers to perform remote code execution, OS command injection, and data tampering. The research highlights the risk posed by insecure edge devices, particularly following a recent cyberattack on Poland's energy grid that exploited similar vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) has issued alerts urging critical infrastructure operators to enhance their cybersecurity measures. The vulnerabilities are particularly concerning as they can disrupt operations and compromise data integrity. Both Lantronix and Silex have issued patches in response to these findings. The vulnerabilities are significant due to the potential for widespread impact across various industries reliant on these devices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Forescout Technologies and CVE-2025-70082 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…