Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbi
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-80155 | 10.0 CRITICAL | Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprint |
| CVE-2026-80144 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write |
| CVE-2026-80147 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write |
| CVE-2026-80146 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read |
| CVE-2026-80143 | 9.9 CRITICAL | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read |
| CVE-2026-80154 | 9.6 CRITICAL | Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass |
| CVE-2026-80145 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password |
| CVE-2026-80156 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validati |
| CVE-2026-80152 | 9.1 CRITICAL | Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule |
| CVE-2026-80148 | 8.6 HIGH | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation |
| CVE-2026-80149 | 8.6 HIGH | Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter |
| CVE-2026-80150 | 7.5 HIGH | Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter |
暂无评论