惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
D
Docker
Stack Overflow Blog
Stack Overflow Blog
GbyAI
GbyAI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
M
MIT News - Artificial intelligence
H
Help Net Security
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
L
LangChain Blog
MongoDB | Blog
MongoDB | Blog
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
S
SegmentFault 最新的问题
博客园 - 司徒正美
C
Check Point Blog
B
Blog
Y
Y Combinator Blog
Microsoft Azure Blog
Microsoft Azure Blog
P
Proofpoint News Feed
F
Fortinet All Blogs
美团技术团队
D
DataBreaches.Net

Security Affairs

Digital attacks drive a new wave of cargo theft, FBI says Carding service Jerry’s Store leak exposes 345,000 stolen payment cards Anthropic launches Claude Security to counter rapid AI-Powered exploits SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now Copy Fail: New Linux bug enables Root via page‑cache corruption Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION
Critical BRIDGE:BREAK flaws impact Lantronix and Silex Te...
Pierluigi Pa · 2026-04-22 · via Security Affairs

22 BRIDGE:BREAK flaws hit Lantronix and Silex Technology converters, exposing approximately 20,000 devices to hijacking and data tampering.

Researchers at Forescout Research Vedere Labs found 22 BRIDGE:BREAK flaws in serial-to-IP devices from Lantronix and Silex Technology.

Serial-to-IP converters, also known as serial device servers, connect legacy serial equipment to modern IP networks for remote monitoring and control. They are widely used in sectors like energy (RTUs, relays), industry (PLCs), retail (POS systems), and healthcare (patient monitors). These devices allow organizations to integrate older hardware into TCP/IP networks without replacing existing systems, improving connectivity while extending equipment lifespan.

The experts warn that around 20,000 devices sit exposed online. Attackers can take control of these converters and manipulate the data they transmit, creating serious risks for industrial and enterprise environments.

“We discovered 22 new vulnerabilities in hardware from device makers: Lantronix and Silex.” reads the report published by Forescout. “Also known as ‘serial-to-IP’ and ‘serial device servers’, these innocuous ‘bridge’ devices are exploitable across critical infrastructure industries, including utilities, healthcare, manufacturing, retail, financial services, transportation, and more.”

“Some of these vulnerabilities allow attackers to take full control of mission-critical devices connected via serial links.” added the company.

Researchers analyzed firmware from major serial-to-IP vendors and found widespread security issues. Each device included dozens of software components, thousands of known vulnerabilities, and many existing exploits. A deeper review uncovered 22 new flaws in Lantronix and Silex Technology products, including remote code execution, authentication bypass, firmware tampering, and data exposure.

Researchers identified up to eight vulnerabilities in Lantronix devices (EDS3000PS and EDS5000 series) and 14 in Silex Technology SD330-AC. Below is the list of the flaws:

Attackers could use these weaknesses to shut down communications (DoS), move laterally across industrial networks, or manipulate data in transit. This means they could alter sensor readings or change commands sent to machines, impacting industrial processes, energy systems, or even healthcare devices.

In power grids, devices such as protection relays track voltage and can trigger breakers via SCADA systems, while factories connect CNC machines for centralized control. These setups often rely on serial-to-IP converters.

A typical attack starts when an attacker gains access through exposed edge devices like VPNs or routers. They then exploit vulnerabilities in the converter (e.g., weak authentication or RCE) to take control. Once inside, they can manipulate data in transit—altering sensor readings or commands. For example, stable temperature data can be changed to extreme fluctuations.

Such manipulation can impact railway signaling, fire alarm systems, or fuel management, causing operational disruption or safety risks.

Both Lantronix and Silex addressed the identified vulnerabilities with the following releases:

To reduce risks, organizations should patch systems, replace default credentials, and enforce strong passwords. They should keep serial-to-IP converters off the internet, restrict access to trusted workstations, and segment networks using VLANs or dedicated subnets. Monitoring is key: teams must detect exploitation attempts and unusual data flows that may indicate tampering.

Vendors should adopt secure-by-design practices and a strong SDLC, keep software updated, and track all firmware components. They should harden binaries, test security regularly, and use robust encryption and signing methods. Using modern Linux versions and notifying customers about exposed devices can further reduce risks and improve overall security.

“This research highlights weaknesses in serial-to-IP converters and the risks they can introduce in critical environments. As these devices are increasingly deployed to connect legacy serial equipment to IP networks, vendors and end-users should treat their security implications as a core operational requirement.” concludes the report. “Based on the new vulnerabilities and attack scenarios we demonstrated – and supported by evidence of prior attacks and the availability of detailed deployment information through OSINT – we recommend that organizations patch vulnerable serial-to-IP converter devices as soon as possible:”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, BRIDGE:BREAK flaws)