Executive brief
Lantronix out-of-band management devices used in data centers, telecom networks, and government infrastructure contain an authentication bypass vulnerability in their web management portal. An unauthenticated attacker can exploit a buffer overflow in session cookie handling to read sensitive configuration files, upload arbitrary files, and achieve remote code execution, potentially compromising the entire device and any downstream serial-connected systems.
Technical details
The web management portal uses snprintf with a fixed-size buffer to construct the session cookie file path; supplying a cookie value of specific length causes the path to truncate at a delimiter and enables path traversal to redirect authentication validation to an arbitrary file such as the local user database. This requires no authentication, user interaction, or network positioning beyond reaching the management portal. A successful exploit grants complete code execution on the device and potential access to serial-managed devices downstream.
Affected products
- Lantronix SLC8000 before 9.7.0.5
- Lantronix SLC9000 before 9.7.0.2
- Lantronix EMG8500 before 9.7.0.1
- Lantronix EMG7500 before 9.7.0.1
- Lantronix SLB882 all firmware versions
- Lantronix SLCx-03 all firmware versions
- Lantronix SLCx-02 all firmware versions
Timeline
- 2026-09-21: disclosed: REVRB-LANTERN research published
- 2026-09-22: advisory: CVE-2026-80155 published on NVD
- 2026-09-18: patched: SLC9000 firmware 9.7.0.2 released; SLC8000 firmware 9.7.0.5 and EMG series 9.7.0.1 made available