Skip to main content
Vulnerability Database/CVE-2026-80155

CVE-2026-80155: Lantronix Device Authentication Bypass Vulnerability

CVE-2026-80155 is an authentication bypass flaw in Lantronix SLC8000, EMG8500/EMG7500, and other devices that enables attackers to execute remote code. This post covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-80155 Overview

CVE-2026-80155 is an unauthenticated authentication bypass affecting Lantronix out-of-band management devices. The flaw resides in the web management portal upload endpoint and stems from unsafe use of snprintf when constructing session cookie file paths. Remote attackers can read sensitive configuration files, write files to arbitrary filesystem locations, and achieve remote code execution without credentials. Because these devices manage serial-connected infrastructure, compromise extends beyond the appliance itself.

Critical Impact

Unauthenticated attackers on the network can bypass session validation, exfiltrate the local user database, and gain full control of affected Lantronix appliances and downstream serial-attached systems.

Affected Products

  • Lantronix SLC8000 before firmware v9.7.0.5
  • Lantronix EMG8500 and EMG7500 before firmware v9.7.0.1
  • Lantronix SLB882, SLCx-03, and SLCx-02 (all firmware versions)

Discovery Timeline

  • 2026-09-21 - Technical write-up published by Revrb (Revrb Lantern Overview)
  • 2026-09-22 - CVE-2026-80155 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-80155

Vulnerability Analysis

The web configuration server builds a filesystem path for the session cookie file using snprintf with a fixed-size destination buffer. When an attacker supplies a cookie value of a carefully chosen length, the formatted path exceeds the buffer capacity and is silently truncated. The truncation removes trailing path components that would normally anchor the lookup inside the session directory, leaving a controllable path prefix. This classifies as a path traversal weakness under [CWE-22].

By pairing the truncation with traversal sequences in the cookie value, the attacker redirects authentication validation to an arbitrary on-disk file. Pointing the check at the local user database causes the session validator to treat unauthenticated requests as valid sessions. All downstream authorization checks then pass, exposing the upload endpoint to any network-reachable attacker.

Root Cause

The root cause is unsafe reliance on snprintf return handling and a lack of canonicalization on attacker-controlled cookie input. The developer treated buffer truncation as benign and did not reject or normalize path segments derived from the cookie. The session validator additionally trusts whatever file the constructed path resolves to, without verifying that the file lives within the session store.

Attack Vector

Exploitation requires only network access to the web management interface and no prior credentials or user interaction. An attacker issues an HTTP request with a crafted Cookie header whose length triggers the truncation and whose contents perform traversal to a chosen target file. Once authentication is bypassed, the same session context permits invocation of the file upload endpoint, allowing writes to arbitrary filesystem paths and, subsequently, remote code execution. Refer to the VulnCheck Advisory on Lantronix for the full exploitation chain.

Detection Methods for CVE-2026-80155

Indicators of Compromise

  • Unusual or oversized Cookie header values in web management portal access logs, particularly containing ../ sequences or unusually long token strings.
  • Unexpected write operations under system directories such as /etc/, /tmp/, or web root paths originating from the web server process.
  • New or modified files in cron directories, startup scripts, or web content directories that correlate with upload endpoint requests.
  • Outbound connections from the appliance to unfamiliar hosts following inbound requests to the upload endpoint.

Detection Strategies

  • Alert on HTTP requests to the web management upload endpoint that lack a preceding successful authentication event.
  • Baseline normal cookie length and flag requests whose cookie values exceed expected bounds or contain traversal metacharacters.
  • Correlate configuration file reads and file writes on the appliance with source IP addresses that never completed the login flow.

Monitoring Recommendations

  • Forward Lantronix web server logs and syslog data to a centralized SIEM for retention and correlation.
  • Monitor egress from out-of-band management VLANs, which should normally have minimal outbound traffic.
  • Track firmware version inventory across all SLC, EMG, and SLB devices to identify unpatched appliances.

How to Mitigate CVE-2026-80155

Immediate Actions Required

  • Upgrade SLC8000 to firmware v9.7.0.5 or later and EMG8500/EMG7500 to firmware v9.7.0.1 or later from the Lantronix SLC8000 Firmware, Lantronix EMG 8500 Firmware, and Lantronix EMG 7500 Firmware directories.
  • Remove SLB882, SLCx-03, and SLCx-02 devices from network-reachable exposure; these end-of-life models have no fixed firmware.
  • Rotate all local user credentials, SSH keys, and API tokens stored on affected appliances after patching.
  • Audit serial-connected downstream devices for evidence of unauthorized configuration changes.

Patch Information

Lantronix has released fixed firmware for supported product lines. Apply v9.7.0.5R2 for SLC8000 and v9.7.0.1R2 for EMG7500 and EMG8500. Legacy SLB882, SLCx-03, and SLCx-02 devices do not have a vendor patch and require compensating controls or replacement.

Workarounds

  • Restrict web management portal access to a dedicated management network using firewall access control lists.
  • Place affected appliances behind a VPN or zero-trust network access gateway that enforces authentication before reaching the web interface.
  • Disable the web management portal where practical and administer devices via console or SSH only.
  • Deploy network intrusion prevention rules that block requests containing traversal patterns in cookie headers targeted at Lantronix management URIs.
bash
# Example iptables rule restricting web management access to a jump host
iptables -A INPUT -p tcp --dport 443 -s 10.10.50.25 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROP
iptables -A INPUT -p tcp --dport 80  -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.