Junglewise Threat Intelligence

CVE-2026-80143: Lantronix SLC/EMG/SLB out-of-band management devices command injection

CVE-2026-80143 · Severity: critical · CVSS 9.9 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices used to remotely control serial-attached infrastructure in data centers, telecom networks, and government facilities contain a command injection flaw in their CLI interface. An attacker with login credentials can execute arbitrary commands with root privileges, potentially compromising the device and any systems it manages, as well as using it as a foothold into the broader network.

Technical details

The vulnerability exists in an undocumented "mfc eeprom read" CLI command that passes unsanitized user input directly to a system() call. An authenticated attacker can inject shell metacharacters into the command parameter to break out and execute arbitrary commands as root. Patches are available for SLC8000/SLC9000 (v9.7.0.2+) and EMG-series (v9.7.0.1+), but no patches exist for SLB882, SLCx-02, and SLCx-03 devices.

Affected products

  • Lantronix SLC8000 before v9.7.0.2
  • Lantronix SLC9000 before v9.7.0.2
  • Lantronix EMG8500 before v9.7.0.1
  • Lantronix EMG7500 before v9.7.0.1
  • Lantronix SLB882 all versions
  • Lantronix SLCx-03 all versions
  • Lantronix SLCx-02 all versions

Timeline

  • 2026-09-21: disclosed
  • 2026-09-22: advisory

References

Related threats