Vendor
Lantronix vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 21 vulnerabilities in Lantronix: 13 in the last 7 days and 13 in the last 90 days, 15 of them critical and 1 exploited in the wild. The most recent, CVE-2026-80156, was published on 22 September 2026. 12 technologies have a page of their own.
- Last 7 days
- 13
- Last 90 days
- 13
- Critical, all time
- 15
- Exploited in the wild
- 1
About Lantronix
A provider of hardware and software solutions for the Internet of Things (IoT) and remote management.
Lantronix technologies
- Lantronix EDS50085
- Lantronix Eds5008 Firmware5
- Lantronix EDS50165
- Lantronix Eds5016 Firmware5
- Lantronix EDS50325
- Lantronix Eds5032 Firmware5
- Lantronix EDS5000 firmware4
- Lantronix EDS3000PS firmware3
- Lantronix Eds3008ps1ns3
- Lantronix EDS3008PS1NS firmware3
- Lantronix Eds3016ps1ns3
- Lantronix EDS3016PS1NS firmware3
Latest Lantronix vulnerabilities
- CVE-2026-80156: Lantronix SLC8000/SLC9000/EMG series path traversal RCE in web uploadcriticalCVSS 9.1EPSS 1.1%
- CVE-2026-80155: Lantronix SLC8000 SLC9000 EMG authentication bypass in web management portalcriticalCVSS 10EPSS 1.7%
- CVE-2026-80154: Lantronix Autonomous Out-of-Band Devices authentication bypass in web managementcriticalCVSS 9.6EPSS 0.6%
- CVE-2026-80152: Lantronix Autonomous Out-of-Band Device command injection in CLIcriticalCVSS 9.1EPSS 2.7%
- CVE-2026-80151: Lantronix out-of-band management devices command injection in NFS downloadcriticalCVSS 9.1EPSS 2.7%
- CVE-2026-80150: Lantronix SLC/EMG/SLB out-of-band management server-side request forgeryhighCVSS 7.5EPSS 0.6%
- CVE-2026-80149: Lantronix SLC8000/SLC9000/EMG series server-side request forgery in WebSSHhighCVSS 8.6EPSS 0.6%
- CVE-2026-80148: Lantronix SLC8000/SLC9000/EMG8500/EMG7500 server-side request forgeryhighCVSS 8.6EPSS 0.6%
- CVE-2026-80147: Lantronix SLC8000/SLC9000 stack buffer overflow in mfc eeprom commandcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-80146: Lantronix SLC/EMG/SLB series stack buffer overflow in EEPROM commandcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-80145: Lantronix SLC/EMG/SLB devices command injection in CIFS passwordcriticalCVSS 9.1EPSS 2.7%
- CVE-2026-80144: Lantronix SLC/EMG/SLB series command injection in eeprom writecriticalCVSS 9.9EPSS 3.0%
- CVE-2026-80143: Lantronix SLC/EMG/SLB out-of-band management devices command injectioncriticalCVSS 9.9EPSS 3.0%
- CVE-2025-70082: Lantronix EDS3000PS unverified password change in ltrx_evocriticalCVSS 9.8EPSS 0.5%
- CVE-2025-67041: Lantronix EDS3000PS OS command injection in TFTP clientcriticalCVSS 9.8EPSS 0.4%
- CVE-2025-67039: Lantronix EDS3000PS authentication bypass in management pagescriticalCVSS 9.1EPSS 0.4%
- CVE-2025-67038: Lantronix EDS5000 OS command injection in HTTP RPC modulecriticalexploited in the wildCVSS 9.8EPSS 0.5%
- CVE-2025-67037: Lantronix EDS5000 OS command injection in tunnel parameterhighCVSS 8.8EPSS 0.4%
- CVE-2025-67036: Lantronix EDS5000 OS command injection in Log Info pagehighCVSS 8.8EPSS 0.4%
- CVE-2025-67035: Lantronix EDS5000 OS command injection in SSH management pagescriticalCVSS 9.8EPSS 0.4%
- CVE-2025-67034: Lantronix EDS5000 OS command injection in SSL credential deletionhighCVSS 8.8EPSS 0.5%
Most severe Lantronix vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-67038: Lantronix EDS5000 OS command injection in HTTP RPC modulecriticalexploited in the wildCVSS 9.8EPSS 0.5%
- CVE-2026-80155: Lantronix SLC8000 SLC9000 EMG authentication bypass in web management portalcriticalCVSS 10EPSS 1.7%
- CVE-2026-80144: Lantronix SLC/EMG/SLB series command injection in eeprom writecriticalCVSS 9.9EPSS 3.0%
- CVE-2026-80143: Lantronix SLC/EMG/SLB out-of-band management devices command injectioncriticalCVSS 9.9EPSS 3.0%
- CVE-2026-80147: Lantronix SLC8000/SLC9000 stack buffer overflow in mfc eeprom commandcriticalCVSS 9.9EPSS 0.9%
- CVE-2026-80146: Lantronix SLC/EMG/SLB series stack buffer overflow in EEPROM commandcriticalCVSS 9.9EPSS 0.9%
- CVE-2025-70082: Lantronix EDS3000PS unverified password change in ltrx_evocriticalCVSS 9.8EPSS 0.5%
- CVE-2025-67041: Lantronix EDS3000PS OS command injection in TFTP clientcriticalCVSS 9.8EPSS 0.4%
- CVE-2025-67035: Lantronix EDS5000 OS command injection in SSH management pagescriticalCVSS 9.8EPSS 0.4%
- CVE-2026-80154: Lantronix Autonomous Out-of-Band Devices authentication bypass in web managementcriticalCVSS 9.6EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 13 | 10 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/lantronix.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Lantronix vulnerabilities", https://junglewise.ai/threats/vendors/lantronix, 26 September 2026.