PatchSiren

LANTRONIX CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL LANTRONIX CVE published 2026-09-22

CVE-2026-80152

Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices have a command injection vulnerability. Authenticated attackers with services permission can execute arbitrary shell commands as root, potentially impacting device and downstream serial-attached devices. This vulnerability allows attackers to achieve complete loss of confidentiality, integrity, and availability on the affected device. System adminis [truncated]

CRITICAL LANTRONIX CVE published 2026-09-22

CVE-2026-80151

Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 devices have a command injection vulnerability in the set nfs download command. Authenticated attackers with services permission can execute arbitrary shell commands as root, potentially impacting device and downstream serial-attached device confidentiality, integrity, and availability.

HIGH LANTRONIX CVE published 2026-09-22

CVE-2026-80150

Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices have a server-side request forgery vulnerability in the WebSSH/WebTelnet listener. This allows unauthenticated attackers to cause the affected device to establish Telnet connections to arbitrary endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter, an attac [truncated]

HIGH LANTRONIX CVE published 2026-09-22

CVE-2026-80149

Lantronix device users should assess exposure and prioritize patching due to a server-side request forgery vulnerability in WebSSH/WebTelnet listeners. Attackers can use this to connect to internal network endpoints. The vulnerability affects Lantronix SLC8000, SLC9000, EMG8500/EMG7500, and SLB882 devices, allowing unauthenticated attackers to establish SSH connections to attacker-controlled endpoints. Us [truncated]

HIGH LANTRONIX CVE published 2026-09-22

CVE-2026-80148

Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices have a server-side request forgery vulnerability in the WebSSH/WebTelnet listener. This allows unauthenticated attackers to establish SSH connections to attacker-controlled endpoints. The vulnerability arises from the custom shellinaboxd build's use of a snprintf call with user-supplied input, which can be exploited by providing an overlong username [truncated]

CRITICAL LANTRONIX CVE published 2026-09-22

CVE-2026-80146

CVE-2026-80146 is a stack-based buffer overflow vulnerability affecting Lantronix SLC8000, SLC9000, EMG8500, and EMG7500 devices. The vulnerability allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read command. This command copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate as [truncated]

HIGH Lantronix CVE published 2025-07-22

CVE-2025-7766

CVE-2025-7766 affects Lantronix Provisioning Manager and is described by CISA as an XML External Entity (XXE) issue in configuration files supplied by network devices. The advisory says the flaw can lead to unauthenticated remote code execution on hosts with Provisioning Manager installed, and Lantronix recommends upgrading to version 7.10.4 or later.

CRITICAL Lantronix CVE published 2025-04-15

CVE-2025-2567

CVE-2025-2567 is a critical Lantronix XPort vulnerability that CISA says can let an attacker modify or disable device settings, disrupt fuel monitoring and supply chain operations, and potentially disable ATG monitoring. The advisory assigns a CVSS 3.1 score of 9.8 and identifies affected XPort firmware in the range >=6.5.0.7 and <7.0.0.3. Lantronix’s remediation includes firmware v8.0.0.0, and the vendor [truncated]