Executive brief
Lantronix out-of-band management devices used in data centers, telecom networks, and government infrastructure contain a stack buffer overflow in an undocumented EEPROM read command. An authenticated attacker can supply oversized input to the CLI or terminal interface to trigger the overflow and execute arbitrary code, gaining complete control of the device and potentially compromising downstream serial-attached systems and credentials stored on the device.
Technical details
A stack-based buffer overflow exists in an undocumented mfc eeprom read command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. The vulnerability requires authentication to the terminal or CLI interface but allows an authenticated attacker to supply oversized input to trigger the overflow and achieve arbitrary code execution. Patches are available for SLC8000 (v9.7.0.2), SLC9000 (v9.7.0.2), and EMG series (v9.7.0.1), but SLB882, SLCx-03, and SLCx-02 devices have no patches available.
Affected products
- Lantronix SLC8000 before 9.7.0.2
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-03 all versions
- Lantronix SLCx-02 all versions
Timeline
- 2026-09-21: disclosed: RE/VRb research disclosure
- 2026-09-22: advisory: NVD publication