Skip to main content
Vulnerability Database/CVE-2026-80151

CVE-2026-80151: Lantronix SLC8000 RCE Vulnerability

CVE-2026-80151 is a command injection RCE flaw in Lantronix SLC8000 devices that enables authenticated attackers to execute shell commands as root. This post covers technical details, affected firmware versions, impact, and mitigation.

Published:

CVE-2026-80151 Overview

CVE-2026-80151 is an operating system command injection vulnerability [CWE-78] affecting Lantronix autonomous out-of-band management devices. The flaw resides in the set nfs download command, which passes unsanitized user input to a system() call. Authenticated attackers holding the services permission can inject shell metacharacters through the terminal or CLI interface to execute arbitrary commands as root. Successful exploitation results in complete compromise of the device and can pivot to serial-attached downstream systems commonly managed through these console servers.

Critical Impact

Authenticated attackers with the services permission can execute arbitrary shell commands as root on affected Lantronix out-of-band management devices, enabling full device takeover and lateral movement to serial-attached infrastructure.

Affected Products

  • Lantronix SLC8000 running firmware versions prior to v9.7.0.3
  • Lantronix EMG8500 and EMG7500 running firmware versions prior to v9.7.0.1
  • Lantronix SLB882, SLCx-03, and SLCx-02 across all firmware versions (end-of-life, no patch)

Discovery Timeline

  • 2026-09-21 - Technical writeup published by Revrb researchers
  • 2026-09-22 - CVE-2026-80151 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-80151

Vulnerability Analysis

The vulnerability affects the console server product line Lantronix markets for autonomous out-of-band management of remote infrastructure. These devices expose a proprietary CLI accessible over network protocols and local serial connections. The set nfs download command allows administrators to fetch configuration or firmware artifacts from a Network File System (NFS) share.

The command handler concatenates user-supplied parameters directly into a shell string and invokes system() on the composite command. No input sanitization, allowlisting, or argument separation is applied. Any user with the services role can supply shell metacharacters such as ;, |, or backticks to break out of the intended argument context.

Because the CLI process runs as root, injected commands inherit root privileges. Compromise of an out-of-band management appliance is particularly consequential: these devices sit on management networks and provide serial console access to routers, switches, servers, and industrial equipment.

Root Cause

The root cause is improper neutralization of special elements used in an OS command [CWE-78]. The affected firmware invokes system() with a shell string built from untrusted CLI parameters, without escaping or using a safe execution primitive such as execve() with a fixed argument vector.

Attack Vector

Exploitation requires network reachability to the CLI or terminal interface and valid credentials for an account holding the services permission. The attacker issues a crafted set nfs download command in which a parameter value contains shell metacharacters followed by the desired command. The injected payload executes as root within the underlying operating system. Technical details are documented in the VulnCheck advisory and the Revrb Lantern writeup.

Detection Methods for CVE-2026-80151

Indicators of Compromise

  • CLI audit log entries containing set nfs download commands with shell metacharacters such as ;, |, &, $(, or backticks in parameter values
  • Unexpected root-owned processes spawned as children of the CLI or management daemon on affected devices
  • Outbound connections from management appliances to unfamiliar hosts, including reverse shells to attacker infrastructure
  • New or modified accounts, SSH keys, or startup scripts on the appliance filesystem

Detection Strategies

  • Centralize syslog from Lantronix devices and alert on any set nfs download invocation containing shell metacharacters
  • Baseline expected administrative activity on out-of-band management devices and flag deviations, especially from accounts with the services role
  • Monitor management network segments for anomalous egress from console servers, which typically should not initiate outbound connections

Monitoring Recommendations

  • Ingest device syslog and authentication events into a SIEM or data lake for long-term retention and correlation
  • Correlate CLI command telemetry with authentication events to identify credential misuse against the services role
  • Alert on process creation or network activity from management appliances that deviates from vendor-documented behavior

How to Mitigate CVE-2026-80151

Immediate Actions Required

  • Upgrade SLC8000 devices to firmware v9.7.0.3 or later and EMG8500/EMG7500 devices to firmware v9.7.0.1 or later
  • Retire or isolate SLB882, SLCx-03, and SLCx-02 devices, which have no available patch
  • Rotate all credentials on affected devices, particularly accounts assigned the services permission
  • Restrict management interface reachability to a dedicated administrative network or jump host

Patch Information

Lantronix has released fixed firmware for supported models. The SLC8000 fix is available at the Lantronix SLC8000 firmware directory. The EMG7500 and EMG8500 fixes are available at the EMG 7500 firmware directory and EMG 8500 firmware directory respectively. No patch exists for SLB882, SLCx-03, or SLCx-02.

Workarounds

  • Remove the services permission from any account that does not strictly require NFS management capabilities
  • Enforce network access control lists to permit CLI and terminal access only from designated administrator workstations
  • Require multi-factor authentication on any jump host that provides access to management appliances
  • Decommission end-of-life models where firmware fixes are not available and replace with supported hardware

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.