Junglewise Threat Intelligence

CVE-2026-80156: Lantronix SLC8000/SLC9000/EMG series path traversal RCE in web upload

CVE-2026-80156 · Severity: critical · CVSS 9.1 · Published 2026-09-22

Technologies: Lantronix SLC9000, Lantronix SLB882, Lantronix SLCx-03, Lantronix SLC8000, Lantronix EMG7500, Lantronix SLCx-02, Lantronix EMG8500. Vendors: Lantronix.

Executive brief

Lantronix out-of-band management devices used in data centers, telecom networks, and government infrastructure contain a path traversal vulnerability in their web management portal. An authenticated attacker can bypass filename validation to write arbitrary files anywhere on the device, achieving complete remote code execution. This could allow takeover of critical infrastructure management systems and downstream serial-connected devices.

Technical details

The web management portal's upload endpoint strips backslash characters but does not validate forward slashes afterward; an attacker providing a filename with both characters can write arbitrary files outside the intended directory. Exploitation requires authentication and network access to the management portal. Successful exploitation grants complete arbitrary code execution on the affected device with full confidentiality, integrity, and availability compromise.

Affected products

  • Lantronix SLC8000 before v9.7.0.5
  • Lantronix SLC9000 before v9.7.0.2
  • Lantronix EMG8500 before v9.7.0.1
  • Lantronix EMG7500 before v9.7.0.1
  • Lantronix SLB882 all versions
  • Lantronix SLCx-03 all versions
  • Lantronix SLCx-02 all versions

Timeline

  • 2026-09-22: disclosed: CVE-2026-80156 published

References

Related threats