PatchSiren cyber security CVE debrief
CVE-2026-80152 LANTRONIX CVE debrief
Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices have a command injection vulnerability. Authenticated attackers with services permission can execute arbitrary shell commands as root, potentially impacting device and downstream serial-attached devices. This vulnerability allows attackers to achieve complete loss of confidentiality, integrity, and availability on the affected device. System administrators and security teams should assess exposure and prioritize remediation to prevent potential security breaches.
- Vendor
- LANTRONIX
- Product
- SLC8000
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-22
- Original CVE updated
- 2026-09-26
- Advisory published
- 2026-09-22
- Advisory updated
- 2026-09-26
Who should care
System administrators and security teams responsible for Lantronix devices should assess exposure and prioritize remediation. This vulnerability can impact device confidentiality, integrity, and availability, as well as downstream serial-attached devices.
Why it matters
CVE-2026-80152 is a critical command injection vulnerability in Lantronix devices that requires immediate attention from system administrators and security teams. The vulnerability allows authenticated attackers to execute arbitrary shell commands as root, potentially impacting device and downstream device security.
- Potential loss of device confidentiality, integrity, and availability
- Possible impact on downstream serial-attached devices
- Need for verification of affected versions and scope
- Priority for firmware updates and access restriction
Technical summary
The Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices have a command injection vulnerability that allows authenticated attackers with services permission to execute arbitrary shell commands as root. This can be exploited through the set script schedule command, which passes unsanitized user input to a system() call. The vulnerability can be triggered by authenticated attackers with services permission, potentially impacting device and downstream serial-attached devices. Firmware updates are available to mitigate this vulnerability.
Defensive priority
High
Recommended defensive actions
- Review and apply firmware updates for Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices
- Restrict access to the terminal or CLI interface
- Monitor device logs for suspicious activity
- Verify device configurations and user permissions
- Perform vulnerability scanning to identify exposed systems
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability. However, the vendor and affected product information is not comprehensive. Further verification is needed to determine the full scope of affected devices and versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://revrb.net/2026/09/21/revrb-lantern.html
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/SLC9000/9.7.0.2R1/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/emg/EMG_7500/9.7.0.1R2/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/emg/EMG_8500/9.7.0.1R2/
-
Source reference
Unverified legacy reference
URL: https://ts.lantronix.com/ftp/slc8000/9.7.0.3R3/
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-os-command-injection-via-set-script-schedule
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.