PatchSiren cyber security CVE debrief
CVE-2026-80149 LANTRONIX CVE debrief
Lantronix device users should assess exposure and prioritize patching due to a server-side request forgery vulnerability in WebSSH/WebTelnet listeners. Attackers can use this to connect to internal network endpoints. The vulnerability affects Lantronix SLC8000, SLC9000, EMG8500/EMG7500, and SLB882 devices, allowing unauthenticated attackers to establish SSH connections to attacker-controlled endpoints. Users should verify patch deployment, monitor internal network activity, and enumerate exposed devices to prioritize remediation.
- Vendor
- LANTRONIX
- Product
- SLC8000
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-26
Who should care
Lantronix device administrators and security teams should assess exposure and prioritize patching. They should verify patch deployment, monitor internal network activity for suspicious connections, and enumerate exposed devices to prioritize remediation. Security teams should also assess potential for lateral movement and track exceptions and retest remediated assets.
Why it matters
CVE-2026-80149 is a server-side request forgery vulnerability in Lantronix devices that allows attackers to connect to internal network endpoints. Lantronix device administrators and security teams should assess exposure and prioritize patching.
- Verify patch deployment for vulnerable devices
- Monitor internal network activity for suspicious connections
- Enumerate exposed devices and prioritize remediation
- Assess potential for lateral movement
Technical summary
Lantronix SLC8000, SLC9000, EMG8500/EMG7500, and SLB882 devices have a server-side request forgery vulnerability in WebSSH/WebTelnet listeners. Unaunthenticated attackers can cause the device to establish SSH connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the SSH terminal connection to an arbitrary host or IP. This allows attackers to connect to internal network endpoints that would otherwise be inaccessible.
Defensive priority
Patch vulnerable devices, verify inventory, and monitor for suspicious connections
Recommended defensive actions
- Patch Lantronix SLC8000, SLC9000, EMG8500/EMG7500, and SLB882 devices with available firmware updates
- Verify device inventory and configurations
- Monitor for suspicious connections and internal network activity
- Verify patch deployment for vulnerable devices
- Enumerate exposed devices and prioritize remediation
- Assess potential for lateral movement
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. Lantronix provides firmware updates for affected devices. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the SSH terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible. Defenders should verify patch deployment, monitor for suspicious and
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80149 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80149
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80149 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80149
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://revrb.net/2026/09/21/revrb-lantern.html
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/SLC9000/9.7.0.2R1/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/emg/EMG_7500/9.7.0.1R2/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/emg/EMG_8500/9.7.0.1R2/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/slc8000/9.7.0.3R3/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-webssh-ssrf-via-rooturl-parameter
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.