Skip to main content
Vulnerability Database/CVE-2026-80152

CVE-2026-80152: Lantronix Device RCE Vulnerability

CVE-2026-80152 is a command injection RCE vulnerability in Lantronix SLC8000, EMG8500, and EMG7500 devices that allows authenticated attackers to execute arbitrary commands as root. This article covers technical details, affected firmware versions, security impact, and mitigation strategies.

Published:

CVE-2026-80152 Overview

CVE-2026-80152 is an operating system command injection vulnerability [CWE-78] affecting Lantronix out-of-band management devices. The flaw resides in the set script schedule command exposed through the terminal and CLI interfaces. Unsanitized user input is passed directly to a system() call, allowing an authenticated attacker holding the services permission to execute arbitrary shell commands as root. Affected products include Lantronix SLC8000 before firmware v9.7.0.3, EMG8500 and EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882, SLCx-03, and SLCx-02. Successful exploitation results in full compromise of the device and can propagate to downstream serial-attached equipment.

Critical Impact

Authenticated attackers gain root shell access on console servers, exposing every serial-attached device in the environment to lateral compromise.

Affected Products

  • Lantronix SLC8000 firmware versions prior to v9.7.0.3
  • Lantronix EMG8500 and EMG7500 firmware versions prior to v9.7.0.1
  • Lantronix SLB882, SLCx-03, and SLCx-02 (all firmware versions)

Discovery Timeline

  • 2026-09-22 - CVE-2026-80152 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-80152

Vulnerability Analysis

Lantronix SLC, EMG, and SLB console servers provide out-of-band management for serial-attached infrastructure. The management CLI exposes a set script schedule command intended to schedule automation scripts on the device. The vulnerability arises because a user-supplied parameter is concatenated into a shell command line and executed through a system() call without sanitization or argument separation. An attacker who authenticates to the terminal or CLI with the services role can embed shell metacharacters in the parameter to break out of the intended command and run arbitrary binaries as root.

Root Cause

The root cause is improper neutralization of special elements used in an OS command [CWE-78]. The scheduler subroutine builds a shell string from attacker-controlled input and hands it to system(), so characters such as ;, |, `, and $() are interpreted by the shell rather than treated as literal data. There is no allowlist, escape routine, or use of execve-style APIs that would isolate arguments from the command interpreter.

Attack Vector

Exploitation requires network reachability to the device management interface and valid credentials with the services permission. After authenticating to the CLI, the attacker issues the set script schedule command with a malicious value in the vulnerable parameter. The injected payload executes with root privileges on the underlying operating system, granting file system access, credential extraction, firmware modification, and interactive access to every downstream serial console attached to the appliance. See the VulnCheck Advisory: Lantronix OS Command Injection and the Revrb Lantern Overview for full technical details.

Detection Methods for CVE-2026-80152

Indicators of Compromise

  • CLI or terminal sessions issuing set script schedule commands containing shell metacharacters such as ;, |, backticks, or $()
  • Unexpected outbound network connections initiated by the console server management process
  • Unauthorized modifications to /etc, script schedules, or firmware images on the appliance
  • New or altered accounts holding the services permission on Lantronix devices

Detection Strategies

  • Ingest syslog, CLI audit logs, and authentication events from Lantronix SLC, EMG, and SLB devices into a centralized log platform
  • Alert on any invocation of set script schedule outside of documented change windows
  • Baseline normal management traffic patterns and flag anomalous shell-like child processes spawned by the management daemon

Monitoring Recommendations

  • Restrict management-plane access to a dedicated administrative VLAN and monitor east-west traffic to those interfaces
  • Correlate console server authentication events with downstream device access to identify pivoting attempts
  • Monitor firmware version reporting to confirm patched builds remain in place after deployment

How to Mitigate CVE-2026-80152

Immediate Actions Required

  • Upgrade SLC8000 devices to firmware v9.7.0.3 or later and EMG8500/EMG7500 devices to v9.7.0.1 or later
  • Retire or air-gap SLB882, SLCx-03, and SLCx-02 units, since no fixed firmware is available for those models
  • Audit accounts holding the services permission and revoke it from any identity that does not require script scheduling
  • Rotate all credentials on affected devices and on downstream serial-attached systems

Patch Information

Lantronix has published fixed firmware images. Deploy SLC8000 firmware 9.7.0.3R3, EMG7500 firmware 9.7.0.1R2, and EMG8500 firmware 9.7.0.1R2. SLB882, SLCx-03, and SLCx-02 remain unpatched and should be treated as end-of-life for exposure to the services role.

Workarounds

  • Block network access to the CLI and terminal management interfaces from untrusted networks using ACLs or firewall rules
  • Require multi-factor authentication for any account permitted to reach the device management plane
  • Remove the services permission from all accounts until patched firmware is deployed
  • Enable command auditing and forward logs off-device to preserve forensic evidence of exploitation attempts
bash
# Configuration example: verify installed firmware and restrict management access
show version
set network filter ip <admin-subnet>/24 accept
set network filter default drop
show user permissions

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.