Executive brief
Lantronix serial console servers used in data centers, government networks, and infrastructure management contain a command injection flaw in a terminal interface command. An authenticated attacker can inject arbitrary shell commands that execute with root privileges, compromising the device's confidentiality, integrity, and availability, and potentially providing unauthorized access to downstream devices managed through serial connections.
Technical details
The vulnerability exists in an undocumented mfc eeprom write command that passes unsanitized user input directly to a system() call, allowing authenticated terminal or CLI users to inject shell commands. Attack requires authentication to the terminal or CLI interface but no other preconditions. Exploitation grants root-level code execution on the affected device, with potential impact on serial-attached downstream devices; patches are available for some models but not others.
Affected products
- Lantronix SLC8000 before v9.7.0.2
- Lantronix SLC9000 before v9.7.0.2
- Lantronix EMG8500 before v9.7.0.1
- Lantronix EMG7500 before v9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-03 all versions
- Lantronix SLCx-02 all versions
Timeline
- 2026-09-21: disclosed: RE/VRb security research published
- 2026-09-22: advisory: CVE-2026-80144 published