Vulnerabilities · 146 days ago
Serial-to-IP converters turn old serial gear into networked assets, so a flaw in one box can become remote access to legacy OT and healthcare devices. The standard response misses the blast radius: these are not isolated appliances, they are bridges into systems that were never meant to face the internet.
Forescout found 20 vulnerabilities across Lantronix and Silex serial-to-IP converters, with some issues exploitable without authentication. The affected device class is also sold by Moxa, Digi, Advantech, and Perle, and Shodan shows nearly 20,000 internet-exposed systems worldwide across manufacturing, telecom, retail, healthcare, energy, and transportation.
The risk is not limited to exposed units. Attackers can also reach converters on local networks through weak edge devices, which means a foothold near the perimeter can still open a path into field equipment and other legacy endpoints.
4 sources covering this story
BRIDGE:BREAK reveals 22 vulnerabilities in serial-to-IP converters enabling disruption and lateral movement across OT environments.
22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters
22 BRIDGE:BREAK flaws in Lantronix and Silex converters expose nearly 20,000 devices online, enabling takeover and data tampering.
Serial-to-IP Devices Hide Thousands of Old & New Bugs
The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say.
Serial-to-IP Converter Flaws Expose OT and Healthcare Systems to Hacking
Forescout researchers discovered 20 new vulnerabilities in Lantronix and Silex products and described theoretical attack scenarios.
Part of the PlainSec briefing for 2026-04-21