Junglewise Threat Intelligence

CVE-2026-80152: Lantronix Autonomous Out-of-Band Device command injection in CLI

CVE-2026-80152 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices (used to remotely manage network infrastructure in data centers and telecom networks) contain a command injection flaw in their command-line interface. An authenticated attacker with the services permission can inject arbitrary shell commands through the script scheduling feature, gaining root-level access and complete control of the device, potentially affecting downstream systems and data that flow through it.

Technical details

A command injection vulnerability exists in the "set script schedule" CLI command, which passes unsanitized user input directly to a system() call. The flaw requires authentication and the services permission, but allows an attacker to execute arbitrary shell commands as root, compromising confidentiality, integrity, and availability of the affected device and any serial-attached downstream devices it manages.

Affected products

  • Lantronix SLC8000 before 9.7.0.3
  • Lantronix SLC9000 before 9.7.0.2
  • Lantronix EMG8500 before 9.7.0.1
  • Lantronix EMG7500 before 9.7.0.1
  • Lantronix SLB882 all versions
  • Lantronix SLCx-03 all versions
  • Lantronix SLCx-02 all versions

Timeline

  • 2026-09-21: disclosed
  • 2026-09-22: advisory

References

Related threats