Junglewise Threat Intelligence

CVE-2026-80145: Lantronix SLC/EMG/SLB devices command injection in CIFS password

CVE-2026-80145 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices contain a command injection flaw in the CIFS password configuration command. An attacker with service permissions can inject arbitrary shell commands executed as root, compromising confidentiality, integrity, and availability of the device and potentially gaining control over downstream serial-managed systems including network infrastructure and physical equipment.

Technical details

The vulnerability is a command injection in the "set cifs password" command that passes unsanitized user input directly to a system() call. Attackers with the services permission can authenticate via terminal or CLI and inject malicious commands through the unfiltered parameter to achieve remote code execution as root. A fix is available in SLC8000/SLC9000 firmware v9.7.0.2, EMG series v9.7.0.1; SLB882, SLCx-02, and SLCx-03 have no patches.

Affected products

  • Lantronix SLC8000 before 9.7.0.2
  • Lantronix SLC9000 before 9.7.0.2
  • Lantronix EMG8500 before 9.7.0.1
  • Lantronix EMG7500 before 9.7.0.1
  • Lantronix SLB882 all versions
  • Lantronix SLCx-03 all versions
  • Lantronix SLCx-02 all versions

Timeline

  • 2026-09-21: disclosed: Research disclosure by RE/VRb LLC
  • 2026-09-22: advisory: NVD published CVE-2026-80145
  • 2026-09: patched: SLC8000/SLC9000 firmware v9.7.0.2 and EMG series v9.7.0.1 released

References

Related threats