Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-80145: Lantronix SLC/EMG devices let privileged users run any command
CVE-2026-80145 · published 17 days ago
Summary
Older firmware on Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03 and SLCx-02 devices lets anyone with a services‑level login add hidden commands that are run as the system administrator. This can let an attacker take full control of the device and any equipment attached to it. Update the firmware to the latest version and limit services‑level access to trusted personnel only.
What to do
- Update lantronix slc8000 to version 9.7.0.2 or later.
- Update lantronix emg8500 to version 9.7.0.1 or later.
- Update lantronix emg7500 to version 9.7.0.1 or later.
- Update lantronix slc9000 to version 9.7.0.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| lantronix | slc8000 | < 9.7.0.2 |
| lantronix | emg8500 | < 9.7.0.1 |
| lantronix | emg7500 | < 9.7.0.1 |
| lantronix | slb882 | All versions |
| lantronix | slcx-03 | All versions |
| lantronix | slcx-02 | All versions |
| lantronix | slc9000 | < 9.7.0.2 |
Original advisory text
Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set cifs password command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
References
- https://revrb.net/2026/09/21/revrb-lantern.html
- https://ts.lantronix.com/ftp/slc8000/9.7.0.2R1/
- https://ts.lantronix.com/ftp/emg/EMG_8500/9.7.0.1R2/
- https://ts.lantronix.com/ftp/emg/EMG_7500/9.7.0.1R2/
- https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-cl...
- https://ts.lantronix.com/ftp/SLC9000/9.7.0.2R1/
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-78OS Command Injection
Timeline
Published22 Sep 2026
Updated7 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta