Executive brief
Lantronix serial console servers and out-of-band management devices used to control and monitor critical infrastructure contain a command injection flaw in their network file system download functionality. An authenticated attacker with services permissions can inject arbitrary shell commands that execute with root privileges, potentially compromising the device, accessing stored credentials, and gaining control over downstream systems connected via serial ports in data centers, telecom networks, and government facilities.
Technical details
The vulnerability is a command injection flaw in the "set nfs download" CLI command that passes unsanitized user input directly to a system() call, allowing authenticated attackers with services permission to execute arbitrary shell commands as root. Attack requires network access to the CLI interface and valid credentials with services permission. A successful exploit grants complete compromise of the affected device with potential lateral movement to serial-attached downstream devices.
Affected products
- Lantronix SLC8000 before 9.7.0.3
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-03 all versions
- Lantronix SLCx-02 all versions
Timeline
- 2026-09-22: disclosed: Vulnerability publicly disclosed