Plug an internet-facing device server into a public IP and start a packet capture. You won’t wait long. Within minutes, automated scanners find it, fingerprint it, and start hammering the login. No human is watching their screen. No one picked your organization. The bots just walk the entire IPv4 space, again and again, looking for anything that answers. This is the unglamorous core of modern cybersecurity: most attacks aren’t targeted, they’re industrial. And a critical flaw CISA flagged this week shows exactly what happens when one of those answering devices has a hole in it.

What Your Honeypots Hear When Nobody’s Watching

A SANS Internet Storm Center guest diary this week put numbers to something most defenders feel but rarely measure. Running a honeypot, an intentionally exposed system that records everything thrown at it, the analyst captured a relentless stream of automated cybercrime. Connections to telnet, SSH, and obscure management ports. Credential guessing against default username and password pairs. Payloads aimed at known router and IoT bugs, fired off without any reconnaissance into whether the target was even the right kind of device.

That’s the texture of the open internet. Your firewall sees the same traffic the honeypot does. The difference is the honeypot is built to log it, and your edge box probably isn’t. These campaigns run on commodity infrastructure, recycle leaked credential lists, and don’t care who you are. A brute-force attempt against a forgotten serial console in a warehouse closet costs the attacker nothing. If it works, they get a foothold. If it doesn’t, they move on in milliseconds and try the next IP.

The lesson buried in that data: exposure itself is the risk. Every service you put on a public address is enrolled in a global guessing game whether you signed up or not.

A 9.8 Code-Injection Flaw, Two Days To Patch

Lantronix EDS5000 serial device server hardware
Lantronix EDS5000 series device servers bridge serial equipment to networks, which is exactly why exposure hurts.

Now connect that to a real device. CISA warned this week that attackers are actively exploiting CVE-2025-67038, a code-injection flaw in Lantronix EDS5000 series device servers. The CVSS score is 9.8. That’s about as bad as the scale goes, and the rating is earned: code injection means an attacker who reaches the device can run commands of their choosing. CISA added it to the Known Exploited Vulnerabilities catalog and gave federal civilian agencies until June 26, 2026, to apply the fix. If you’re reading this on the day it published, that’s two days.

Device servers like the EDS5000 do an unglamorous but critical job. They bridge old serial equipment, industrial controllers, lab instruments, building systems, to IP networks. They tend to get installed once, configured by whoever set up the equipment, and then forgotten for years. Nobody patches them. Nobody logs into them. Which means nobody notices when an automated scanner finds one and turns a 9.8 code-injection bug into a quiet foothold on your network. The whole point of cyber security for this gear is recognizing that “set and forget” is the same thing as “abandoned.”

The federal deadline is a useful forcing function, but the bug doesn’t care about your sector. If you run any EDS5000 hardware, it’s exposed to the same automated traffic the honeypot recorded, and now there’s a public reason for the bots to care.

Exploited Two Months Before Disclosure

Cisco networking hardware representing the SD-WAN flaw exploited before disclosure
Researchers believe attackers used rogue peering to reach the victim’s Cisco SD-WAN devices and gain root.

Here’s the part that should keep you honest about your patch cadence. Researchers reported that attackers exploited a Cisco SD-WAN flaw roughly two months before it was publicly disclosed. They believe rogue peering was used to connect to the victim’s SD-WAN devices, escalate to admin, and grab root-level access. Read that timeline again. The defenders couldn’t have patched, because there was no patch and no advisory. The vulnerability was a zero-day to everyone except the people using it.

This is why “we patch promptly” is necessary and still not enough. Patching closes the window after a flaw goes public. It does nothing for the window before, and that window can be months. The Cisco case and the Lantronix case bracket the problem neatly. One is a known, cataloged bug with a deadline. The other was a silent foothold that no SLA dashboard would have caught. Defense in depth exists precisely because any single control, including patching, has gaps an attacker can live inside.

The connective tissue across all three stories is the same. Exposed management surfaces, whether a serial console, an SD-WAN appliance, or a honeypot’s open port, are where the automated and the targeted both come knocking. Your threat-protection strategy has to assume the knock is constant and the lock might fail.

Cybersecurity For Exposed Devices: What To Do This Week

None of this requires a new product. It requires treating exposure as something you own and manage, not something that just happens. Start with the things you can do today and keep the ongoing habits that make the next 9.8 a non-event.

Immediate actions, in order of payoff:

  • Inventory every device with a public IP, especially serial servers, KVMs, and management interfaces nobody has logged into in a year.
  • Patch CVE-2025-67038 on any Lantronix EDS5000 hardware now, ahead of the June 26 deadline, and check the CISA KEV catalog for anything else you run.
  • Pull management interfaces off the public internet entirely. Put them behind a VPN or jump host so the bots never reach the login at all.
  • Enforce brute-force controls on anything that must stay reachable: rate limits, lockouts, and automatic IP blocking on repeated failures. Tools like IPBan or IPBan Pro handle this at the firewall layer for Windows and Linux without much fuss.
  • Kill default credentials and require phishing-resistant MFA on every admin path.

The ongoing work matters more than the scramble. Log authentication events from edge devices to an off-box collector, because a compromised device can’t be trusted to report its own breach. Build threat detection around behavior: a serial console that suddenly spawns a shell or reaches out to an unfamiliar host is worth an alert, even if no signature fired. Segment these devices so a foothold on one doesn’t become a path to your crown jewels. And rehearse the incident response, who isolates the device, who pulls logs, who rotates credentials, before you need it at 2 a.m.

Security hardening for forgotten infrastructure isn’t glamorous and it won’t show up on a vendor’s quarterly slide. It’s the difference between being one of the millions of IPs the bots probe and bounce off of, and being the one that answered with a root shell. The honeypots already told you which traffic is coming. The only open question is what your devices say back.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.