Executive brief
Lantronix out-of-band management devices contain a command injection flaw in the CIFS password configuration command. An attacker with service permissions can inject arbitrary shell commands executed as root, compromising confidentiality, integrity, and availability of the device and potentially gaining control over downstream serial-managed systems including network infrastructure and physical equipment.
Technical details
The vulnerability is a command injection in the "set cifs password" command that passes unsanitized user input directly to a system() call. Attackers with the services permission can authenticate via terminal or CLI and inject malicious commands through the unfiltered parameter to achieve remote code execution as root. A fix is available in SLC8000/SLC9000 firmware v9.7.0.2, EMG series v9.7.0.1; SLB882, SLCx-02, and SLCx-03 have no patches.
Affected products
- Lantronix SLC8000 before 9.7.0.2
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-03 all versions
- Lantronix SLCx-02 all versions
Timeline
- 2026-09-21: disclosed: Research disclosure by RE/VRb LLC
- 2026-09-22: advisory: NVD published CVE-2026-80145
- 2026-09: patched: SLC8000/SLC9000 firmware v9.7.0.2 and EMG series v9.7.0.1 released