Skip to main content
Vulnerability Database/CVE-2026-80144

CVE-2026-80144: Lantronix Device RCE Vulnerability

CVE-2026-80144 is a command injection vulnerability in Lantronix SLC8000, SLC9000, EMG8500, EMG7500, and other devices allowing authenticated attackers to execute arbitrary commands as root. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-80144 Overview

CVE-2026-80144 is a command injection vulnerability [CWE-78] affecting Lantronix out-of-band management devices. The flaw resides in an undocumented mfc eeprom write command exposed through the terminal and command-line interface (CLI). The command passes unsanitized user input directly to a system() call, allowing any authenticated user to execute arbitrary shell commands as root. Affected devices include SLC8000 and SLC9000 before firmware v9.7.0.2, EMG8500 and EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882, SLCx-03, and SLCx-02.

Critical Impact

Authenticated attackers gain root-level command execution on console servers, compromising confidentiality, integrity, and availability of the device and any downstream serial-attached equipment.

Affected Products

  • Lantronix SLC8000 and SLC9000 (before firmware v9.7.0.2)
  • Lantronix EMG8500 and EMG7500 (before firmware v9.7.0.1)
  • Lantronix SLB882, SLCx-03, and SLCx-02 (all firmware versions)

Discovery Timeline

  • 2026-09-22 - CVE-2026-80144 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-80144

Vulnerability Analysis

Lantronix console servers expose a management CLI used to configure serial ports, users, and network settings. The CLI includes an undocumented mfc eeprom write command intended for manufacturing operations. The command handler forwards user-supplied parameters into a system() call without sanitization or argument quoting. Any authenticated user with terminal or CLI access can inject shell metacharacters and execute arbitrary commands as root. Because these devices provide out-of-band management to critical infrastructure, successful exploitation can pivot into serial-connected routers, switches, PDUs, and other backend systems.

Root Cause

The vulnerability stems from improper neutralization of special elements used in an operating system command [CWE-78]. The mfc eeprom write handler concatenates attacker-controlled parameters into a shell command string and executes it through system(). No allowlist, escape routine, or execve-style argument separation is applied. Authorization for the undocumented command is not restricted to administrative roles, so low-privileged accounts inherit root command execution capability.

Attack Vector

Exploitation requires network access to the device management interface and valid credentials for any account. An attacker connects to the terminal or CLI over supported transports, authenticates, and issues the mfc eeprom write command with shell metacharacters such as ;, |, or backticks embedded in the argument. The injected payload runs in the root context of the firmware shell. Refer to the VulnCheck Advisory on Lantronix and the RevRB Lantern research write-up for command-level detail.

Detection Methods for CVE-2026-80144

Indicators of Compromise

  • CLI or terminal session logs containing the string mfc eeprom write followed by shell metacharacters such as ;, &&, |, or backticks.
  • Unexpected outbound network connections originating from SLC, EMG, or SLB device management IP addresses.
  • New or modified files under writable firmware paths, or unexpected processes running under the root context on the device.

Detection Strategies

  • Enable centralized syslog forwarding from all Lantronix devices and alert on any use of the mfc eeprom write command, which has no legitimate operational purpose in production.
  • Baseline authenticated CLI activity per user account and flag deviations, particularly commands issued by low-privileged or service accounts.
  • Correlate device authentication events with subsequent egress traffic from the management network to identify post-exploitation activity.

Monitoring Recommendations

  • Ingest console server audit logs into a security data lake and retain them for incident review.
  • Monitor management-plane network segments for lateral movement toward serial-attached infrastructure following successful device logins.
  • Alert on firmware version drift or configuration changes on Lantronix devices outside of approved maintenance windows.

How to Mitigate CVE-2026-80144

Immediate Actions Required

  • Upgrade SLC8000 and SLC9000 devices to firmware v9.7.0.2 and EMG8500 and EMG7500 devices to firmware v9.7.0.1 or later.
  • Retire or isolate SLB882, SLCx-03, and SLCx-02 devices, which have no fixed firmware available.
  • Rotate all local and remote authentication credentials on affected devices, including any accounts used by automation.
  • Audit CLI and terminal session logs for prior use of the mfc eeprom write command.

Patch Information

Lantronix has published fixed firmware images: SLC9000 9.7.0.2R1, SLC8000 9.7.0.2R1, EMG7500 9.7.0.1R2, and EMG8500 9.7.0.1R2. Validate image integrity against vendor-published checksums before deployment.

Workarounds

  • Restrict management interface reachability to a dedicated administrative VLAN protected by firewall rules and jump-host access.
  • Enforce strong, unique credentials and disable any shared or default accounts that could be used for authenticated exploitation.
  • Where feasible, disable remote CLI transports and require console access for administrative sessions until patched firmware is deployed.
bash
# Example ACL restricting Lantronix management access to a bastion host
iptables -A INPUT -p tcp -s 10.10.0.5 --dport 22 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j DROP
iptables -A INPUT -p tcp --dport 23 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.