Executive brief
Lantronix out-of-band management devices contain a server-side request forgery vulnerability in their WebSSH/WebTelnet service that allows unauthenticated attackers to redirect SSH connections to arbitrary hosts. These appliances are widely deployed in data centers, telecommunications networks, government infrastructure, and high-performance computing environments to provide emergency management access to network devices. An attacker exploiting this flaw can enumerate internal network endpoints, intercept communications, or pivot to otherwise inaccessible systems on the managed network.
Technical details
The vulnerability exists in a custom shellinaboxd build where the SSH connection target is constructed using snprintf with user-supplied input from the WebSSH/WebTelnet listener. By supplying an overlong username string, an attacker causes integer truncation of the device IP suffix, allowing redirection to an attacker-controlled endpoint. The flaw requires no authentication and is reachable over the network, enabling reconnaissance and lateral movement within management-layer infrastructure.
Affected products
- Lantronix SLC8000 before 9.7.0.3
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all
- Lantronix SLCx-03 all
- Lantronix SLCx-02 all
Timeline
- 2026-09-22: disclosed
- 2026-09-21: other: Independent research published