Executive brief
Lantronix out-of-band management devices used in data centers, telecommunications, and government networks contain a flaw in their web-based terminal feature that allows attackers without credentials to redirect SSH connections to arbitrary hosts. An attacker can exploit this to probe internal networks or redirect terminal sessions, potentially gaining access to managed devices and serial-connected infrastructure that should be isolated. These devices are commonly deployed as secondary management paths in critical environments including defense and energy facilities.
Technical details
The WebSSH/WebTelnet listener in the custom shellinaboxd implementation fails to properly validate the rooturl parameter, allowing unauthenticated attackers to perform server-side request forgery. By modifying the rooturl parameter in a web request, an attacker can cause the device to establish SSH connections to attacker-controlled endpoints or internal network targets. This enables network reconnaissance and potential lateral movement into otherwise isolated management infrastructure.
Affected products
- Lantronix SLC8000 before v9.7.0.3
- Lantronix SLC9000 before v9.7.0.2
- Lantronix EMG8500 before v9.7.0.1
- Lantronix EMG7500 before v9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-02 all versions
- Lantronix SLCx-03 all versions
Timeline
- 2026-09-22: disclosed: CVE-2026-80149 published