Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80155 | 10.0 CRITICAL | Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprint |
| CVE-2026-80144 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write |
| CVE-2026-80147 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write |
| CVE-2026-80146 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read |
| CVE-2026-80154 | 9.6 CRITICAL | Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass |
| CVE-2026-80145 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password |
| CVE-2026-80156 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validati |
| CVE-2026-80151 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download |
| CVE-2026-80152 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule |
| CVE-2026-80148 | 8.6 HIGH | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation |
| CVE-2026-80149 | 8.6 HIGH | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter |
| CVE-2026-80150 | 7.5 HIGH | Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter |
No comments yet