Serial-to-IP Flaws Expose Legacy OT at Scale

Serial-to-IP converters turn old serial gear into networked assets, so a flaw in one box can become remote access to legacy OT and healthcare devices. The standard response misses the blast radius: these are not isolated appliances, they are bridges into systems that were never meant to face the internet. Forescout found 20 vulnerabilities across Lantronix and Silex serial-to-IP converters, with some issues exploitable without authentication. The affected device class is also sold by Moxa, Digi, Advantech, and Perle, and Shodan shows nearly 20,000 internet-exposed systems worldwide across manufacturing, telecom, retail, healthcare, energy, and transportation. The risk is not limited to exposed units. Attackers can also reach converters on local networks through weak edge devices, which means a foothold near the perimeter can still open a path into field equipment and other legacy endpoints.

Part of the PlainSec briefing for 2026-04-21

Sources