Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80156— Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass

Quick assessment

Affected
LANTRONIX SLC8000
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to

CVSS 9.1 · Critical

Affected Version Matrix 6

VendorProduct Version RangeStatus
LANTRONIX EMG7500 < 9.7.0.1 affected
LANTRONIX EMG8500 < 9.7.0.1 affected
LANTRONIX SLB882 * affected
LANTRONIX SLC8000 < 9.7.0.5 affected
LANTRONIX SLCx-02 * affected
LANTRONIX SLCx-03 * affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80156

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Lantronix Autonomous Out-of-Band Devices Arbitrary File Write via Upload Filename Validation Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Lantronix SLC8000 before firmware v9.7.0.5, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows authenticated attackers to write arbitrary data to any location on the device's filesystem, leading to remote code execution. The upload filename validation strips backslash characters but does not subsequently check for forward slashes when a backslash is detected; by supplying a filename containing both characters an attacker writes outside the intended upload directory to any writable path. Attackers can use this vulnerability to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-connected devices.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
LANTRONIX SLC8000 0 ~ 9.7.0.5 -
LANTRONIX EMG8500 0 ~ 9.7.0.1 -
LANTRONIX EMG7500 0 ~ 9.7.0.1 -
LANTRONIX SLB882 * -
LANTRONIX SLCx-03 * -
LANTRONIX SLCx-02 * -

II. Public POCs for CVE-2026-80156

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80156

登录查看更多情报信息。

Other References for CVE-2026-80156 (5)

Same Patch Batch · LANTRONIX · 2026-09-22 · 13 CVEs total

CVE-2026-80155 10.0 CRITICAL Lantronix Autonomous Out-of-Band Devices Unauthenticated Authentication Bypass via snprint
CVE-2026-80144 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom write
CVE-2026-80147 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom write
CVE-2026-80146 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices Stack-Based Buffer Overflow via mfc eeprom read
CVE-2026-80143 9.9 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via mfc eeprom read
CVE-2026-80154 9.6 CRITICAL Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass
CVE-2026-80145 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices CLI Command Injection via set cifs password
CVE-2026-80151 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download
CVE-2026-80152 9.1 CRITICAL Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule
CVE-2026-80148 8.6 HIGH Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation
CVE-2026-80149 8.6 HIGH Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter
CVE-2026-80150 7.5 HIGH Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-80156

No comments yet


Leave a comment