Last Updated: 2026-06-26T19:06:23Z
What’s Happening
Forescout reports on a recently-active exploitation campaign targeting Lantronix and OpenWRT LuCI endpoints.
The observed attacks came from two putatively distinct sources—one which was exploiting CVE-2025-67038, an authenticated command injection vulnerability in Lantronix/OpenWRT LuCI, and another which was performing brute force authentication against the endpoints, but without attempted exploitation of the same vulnerability.
More context from @darses:
Actions
If you have these devices on your network, review logs for suspicious activity. Review the IoCs listed by forescout for presence in your environment.
Also maybe don’t have these things open to the internet? Certainly not admin consoles, sheesh.
Indicators of Compromise
Since the Forescout list is truncated, here’s an extracted list of IoCs from the article.
| Value | Type | Description |
|---|---|---|
| 38.207.136[.]2 | IPv4 | Chaya_006 scanner — Apr 5-7 — Japan — CVE-2025-67038 exploitation |
| 160.238.37[.]28 | IPv4 | Chaya_006 scanner — Apr 27 — South Korea — LuCI reconnaissance |
| 59.124.166[.]52 | IPv4 | Chaya_006 scanner — Apr 27 — Taiwan — brute force on rpc/auth |
| 218.13.42[.]36 | IPv4 | Chaya_006 scanner — Jun 3 — China — UA: openwrt-login-checker/2.0 |
| 154.219.113[.]56 | IPv4 | Chaya_006 C2 — Apr 5 — Hong Kong — capability test callbacks lntxe1-a |
| 38.180.201[.]49 | IPv4 | Chaya_006 C2 — Apr 6 — Japan — callback path /ltrx_eds5k_rpc |
| hxxp://154.219.113[.]56/lntxe1 | URL | Chaya_006 C2 callback — wget capability test |
| hxxp://154.219.113[.]56/lntxe2 | URL | Chaya_006 C2 callback — busybox wget capability test |
| hxxp://154.219.113[.]56/lntxe3 | URL | Chaya_006 C2 callback — curl capability test |
| hxxp://154.219.113[.]56/lntxe4 | URL | Chaya_006 C2 callback — wget /dev/null capability test |
| hxxp://154.219.113[.]56/lntxe5 | URL | Chaya_006 C2 callback — /usr/bin/wget capability test |
| hxxp://154.219.113[.]56/lntxe6 | URL | Chaya_006 C2 callback — python urllib capability test |
| hxxp://154.219.113[.]56/lntxe7 | URL | Chaya_006 C2 callback — nslookup capability test |
| hxxp://154.219.113[.]56/lntxe8 | URL | Chaya_006 C2 callback — echo /dev/tcp capability test |
| hxxp://154.219.113[.]56/lntxe9 | URL | Chaya_006 C2 callback — wget capability test |
| hxxp://154.219.113[.]56/lntxea | URL | Chaya_006 C2 callback — wget capability test |
| hxxp://38.180.201[.]49/ltrx_eds5k_rpc | URL | Chaya_006 C2 callback — Lantronix EDS5000 RPC fingerprint |
| lntxe7.154.219.113.56.nip[.]io | Domain | Chaya_006 DNS callback via nip.io wildcard DNS |
| openwrt-login-checker/2.0 | User-Agent | Custom UA — brute force scanner targeting OpenWRT LuCI (Jun 3) |
Notes
Thanks to @darses for the tip!
Be advised that the “IoCs” table at the bottom of that post is unusable, as something has resulted in the IPs’ first octets being stripped.
