Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-80145: Lantronix SLC/EMG devices let privileged users run any command

CVE-2026-80145 · published 17 days ago
Summary

Older firmware on Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03 and SLCx-02 devices lets anyone with a services‑level login add hidden commands that are run as the system administrator. This can let an attacker take full control of the device and any equipment attached to it. Update the firmware to the latest version and limit services‑level access to trusted personnel only.

What to do
  • Update lantronix slc8000 to version 9.7.0.2 or later.
  • Update lantronix emg8500 to version 9.7.0.1 or later.
  • Update lantronix emg7500 to version 9.7.0.1 or later.
  • Update lantronix slc9000 to version 9.7.0.2 or later.
Affected software
VendorProductAffected versions
lantronix slc8000 < 9.7.0.2
lantronix emg8500 < 9.7.0.1
lantronix emg7500 < 9.7.0.1
lantronix slb882 All versions
lantronix slcx-03 All versions
lantronix slcx-02 All versions
lantronix slc9000 < 9.7.0.2
Original advisory text
Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set cifs password command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
2% chance of attack within 30 days
Type
CWE-78OS Command Injection
Timeline
Published22 Sep 2026
Updated7 Oct 2026
First seen22 Sep 2026
Sources
CVE-2026-80145 · MITRE
Track software like this
Free during beta