Junglewise Threat Intelligence

CVE-2026-80154: Lantronix Autonomous Out-of-Band Devices authentication bypass in web management

CVE-2026-80154 · Severity: critical · CVSS 9.6 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices used in data centers, telecommunications, and government networks contain a critical authentication bypass in their web management portal. Attackers can derive predictable session tokens and bypass IP validation to gain administrative control of these devices, which often control access to critical infrastructure and serial-connected systems. Successful exploitation could allow attackers to compromise network management capabilities and gain access to downstream devices in sensitive environments.

Technical details

Session tokens are generated deterministically based only on device model and current time at one-second resolution, making them enumerable by unauthenticated attackers. The vulnerability combines weak token generation with a URI-based path routing flaw that bypasses per-session source-address validation, allowing an attacker to derive a valid token from one IP address and reuse it from another. This enables unauthenticated remote code execution and potential compromise of serial-attached infrastructure management devices.

Affected products

  • Lantronix SLC8000 all versions
  • Lantronix SLC9000 all versions
  • Lantronix EMG8500 all versions
  • Lantronix EMG7500 all versions
  • Lantronix SLB882 all versions
  • Lantronix SLCx-03 all versions
  • Lantronix SLCx-02 all versions

Timeline

  • 2026-09-22: disclosed
  • 2026-09-21: other: Researcher report published detailing 14 discovered vulnerabilities in Lantronix devices

References

Related threats