Executive brief
Lantronix out-of-band management devices used in data centers, telecom networks, and government infrastructure contain a path traversal vulnerability in their web management portal. An authenticated attacker can bypass filename validation to write arbitrary files anywhere on the device, achieving complete remote code execution. This could allow takeover of critical infrastructure management systems and downstream serial-connected devices.
Technical details
The web management portal's upload endpoint strips backslash characters but does not validate forward slashes afterward; an attacker providing a filename with both characters can write arbitrary files outside the intended directory. Exploitation requires authentication and network access to the management portal. Successful exploitation grants complete arbitrary code execution on the affected device with full confidentiality, integrity, and availability compromise.
Affected products
- Lantronix SLC8000 before v9.7.0.5
- Lantronix SLC9000 before v9.7.0.2
- Lantronix EMG8500 before v9.7.0.1
- Lantronix EMG7500 before v9.7.0.1
- Lantronix SLB882 all versions
- Lantronix SLCx-03 all versions
- Lantronix SLCx-02 all versions
Timeline
- 2026-09-22: disclosed: CVE-2026-80156 published