CVE-2026-80148: Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via Username Truncation
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish SSH connections to attacker-controlled endpoints. The custom shellinaboxd builds its SSH connection target using a snprintf call with user-supplied input; by supplying an overlong username string an attacker causes the device IP suffix to be truncated, redirecting the resulting connection to an arbitrary host. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix SLC8000to a version that resolves this vulnerability.Fixed in v9.7.0.3 - Upgrade
Upgrade
Lantronix EMG8500/EMG7500to a version that resolves this vulnerability.Fixed in v9.7.0.1
Event History
Frequently Asked Questions
Which devices have a firmware update identified as addressing this issue?
SLC8000 is affected before firmware v9.7.0.3, and EMG8500 and EMG7500 are affected before firmware v9.7.0.1. The supplied references include v9.7.0.3R3 for SLC8000 and v9.7.0.1R2 for EMG8500.
Does an attacker need credentials or user interaction to exploit this?
No. Exploitation is described as unauthenticated and requires no user interaction.
What systems are at risk of being reached through an affected device?
An attacker can cause the device to establish SSH connections to attacker-controlled endpoints and may enumerate or communicate with internal network endpoints that would otherwise be inaccessible. This makes networks reachable from the device a relevant exposure boundary.
Is there a fixed firmware version listed for SLB882?
No. The issue is stated to affect all firmware versions of SLB882, and the provided data does not identify a remediating SLB882 firmware version.