Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Ex-Pinterest Team Redesigns Email with Extra — It’s Actually Better

22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters

Ransomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » 22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters
Identity

22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters

By April 21, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 21, 2026Network security/vulnerabilities

Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex. These vulnerabilities could be exploited to hijack a susceptible device and alter data exchanged by the device.

Forescout Research Vedere Labs has identified approximately 20,000 serial-to-Ethernet converters with the vulnerabilities, collectively codenamed BRIDGE:BREAK, exposed online worldwide.

“Some of these vulnerabilities could allow attackers to gain complete control over mission-critical devices connected via serial links,” the cybersecurity firm said in a report shared with The Hacker News.

A serial-to-IP converter is a hardware device that allows users to remotely access, control, and manage any serial device over an IP network or the Internet by “bridging” legacy applications running on TCP/IP with industrial control systems (ICS).

Broadly speaking, 8 security flaws were discovered in Lantronix products (EDS3000PS series and EDS5000 series) and as many as 14 in Silex SD330-AC. These drawbacks fall into the following broad categories:

Remote code execution – CVE-2026-32955, CVE-2026-32956, CVE-2026-32961, CVE-2025-67041, CVE-2025 -67034, CVE-2025-67035, CVE-2025-67036, CVE-2025-67037, and CVE-2025-67038 Client-side Code Execution – CVE-2026-32963 Denial of Service (DoS) – CVE-2026-32961, CVE-2015-5621, CVE-2024-24487 Authentication Bypass – CVE-2026-32960, CVE-2025-67039 Device Takeover – FSCT-2025-0021 (CVE (No assignment), CVE-2026-32965, CVE-2025-70082 Firmware tampering – CVE-2026-32958 Configuration tampering – CVE-2026-32962, CVE-2026-32964 Information leakage – CVE-2026-32959 Arbitrary file upload – CVE-2026-32957

Successful exploitation of the aforementioned flaws could allow an attacker to disrupt serial communications with field assets, perform lateral movement, tamper with sensor values, or alter actuator behavior.

In a hypothetical attack scenario, an attacker could gain initial access to a remote facility through an Internet-exposed edge device, such as an industrial router or firewall, and weaponize the BRIDGE:BREAK vulnerability to compromise the serial-to-IP converter and alter serial data sent to and from the IP network.

Lantronix and Silex have released security updates to address identified issues –

In addition to patching, users are encouraged to replace default credentials, avoid using weak passwords, segment networks to prevent attackers from reaching vulnerable serial-to-IP converters or using them as transit points to other critical assets, and prevent devices from being exposed to the Internet.

“This research highlights weaknesses in serial-to-IP converters and the risks they can pose to critical environments,” Forescout said. “As these devices are increasingly deployed to connect traditional serial equipment to IP networks, vendors and end users must treat security implications as a core operational requirement.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRansomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack
Next Article Ex-Pinterest Team Redesigns Email with Extra — It’s Actually Better

Related Posts

Ransomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack

April 21, 2026

5 places mature SOCs keep their MTTR fast and other SOCs are wasting their time

April 21, 2026

How attackers get in through your front door via identity-based attacks

April 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ex-Pinterest Team Redesigns Email with Extra — It’s Actually Better

22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters

Ransomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack

IFBF2026 – It’s time for flow batteries!

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.