Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80152— Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule

Quick assessment

Affected
LANTRONIX SLC8000
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbi

CVSS 9.1 · Critical

Affected Version Matrix 6

VendorProduct Version RangeStatus
LANTRONIX EMG7500 < 9.7.0.1 affected
LANTRONIX EMG8500 < 9.7.0.1 affected
LANTRONIX SLB882 * affected
LANTRONIX SLC8000 < 9.7.0.2 affected
LANTRONIX SLCx-02 * affected
LANTRONIX SLCx-03 * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80152

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule
Source: CVE Program / CVE List V5
Vulnerability Description
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set script schedule command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
LANTRONIX SLC8000 0 ~ 9.7.0.2 -
LANTRONIX EMG8500 0 ~ 9.7.0.1 -
LANTRONIX EMG7500 0 ~ 9.7.0.1 -
LANTRONIX SLB882 * -
LANTRONIX SLCx-03 * -
LANTRONIX SLCx-02 * -

II. Public POCs for CVE-2026-80152

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80152

登录查看更多情报信息。

Other References for CVE-2026-80152 (5)

Same Patch Batch · LANTRONIX · 2026-09-22 · 13 CVEs total

CVE-2026-80155 10.0 CRITICAL Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprint
CVE-2026-80144 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write
CVE-2026-80147 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write
CVE-2026-80146 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read
CVE-2026-80143 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read
CVE-2026-80154 9.6 CRITICAL Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass
CVE-2026-80145 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password
CVE-2026-80156 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validati
CVE-2026-80151 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download
CVE-2026-80148 8.6 HIGH Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation
CVE-2026-80149 8.6 HIGH Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter
CVE-2026-80150 7.5 HIGH Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-80152

No comments yet


Leave a comment