Junglewise Threat Intelligence

CVE-2026-80148: Lantronix SLC8000/SLC9000/EMG8500/EMG7500 server-side request forgery

CVE-2026-80148 · Severity: high · CVSS 8.6 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices contain a server-side request forgery vulnerability in their WebSSH/WebTelnet service that allows unauthenticated attackers to redirect SSH connections to arbitrary hosts. These appliances are widely deployed in data centers, telecommunications networks, government infrastructure, and high-performance computing environments to provide emergency management access to network devices. An attacker exploiting this flaw can enumerate internal network endpoints, intercept communications, or pivot to otherwise inaccessible systems on the managed network.

Technical details

The vulnerability exists in a custom shellinaboxd build where the SSH connection target is constructed using snprintf with user-supplied input from the WebSSH/WebTelnet listener. By supplying an overlong username string, an attacker causes integer truncation of the device IP suffix, allowing redirection to an attacker-controlled endpoint. The flaw requires no authentication and is reachable over the network, enabling reconnaissance and lateral movement within management-layer infrastructure.

Affected products

  • Lantronix SLC8000 before 9.7.0.3
  • Lantronix SLC9000 before 9.7.0.2
  • Lantronix EMG8500 before 9.7.0.1
  • Lantronix EMG7500 before 9.7.0.1
  • Lantronix SLB882 all
  • Lantronix SLCx-03 all
  • Lantronix SLCx-02 all

Timeline

  • 2026-09-22: disclosed
  • 2026-09-21: other: Independent research published

References

Related threats