Executive brief
Lantronix out-of-band serial console servers used in data centers, telecom networks, and government infrastructure contain a stack buffer overflow vulnerability in an undocumented firmware command. An authenticated attacker can supply oversized input to the mfc eeprom write command to execute arbitrary code with full device privileges, compromising the device and any serial-attached systems it manages, such as network infrastructure or physical plant controls.
Technical details
The vulnerability is a stack-based buffer overflow in an undocumented mfc eeprom write command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate to the terminal or CLI interface as any user and trigger the overflow by supplying oversized input, achieving remote code execution. The SLB882, SLCx-02, and SLCx-03 device lines are affected across all firmware versions with no patches planned; SLC8000/SLC9000 and EMG series have fixes available in recent firmware releases.
Affected products
- Lantronix SLC8000 before 9.7.0.2
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all firmware versions
- Lantronix SLCx-03 all firmware versions
- Lantronix SLCx-02 all firmware versions
Timeline
- 2026-09-21: disclosed: Research disclosed by RE/VRb LLC
- 2026-09-22: advisory: CVE-2026-80147 published
- 2026-09-18: patched: Firmware 9.7.0.2 for SLC9000 released; 9.7.0.1 for EMG series