CVE-2026-80152: Lantronix Autonomous Out-of-Band Devices OS Command Injection via set script schedule
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set script schedule command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix SLC8000to a version that resolves this vulnerability.Fixed in 9.7.0.3 - Upgrade
Upgrade
Lantronix EMG8500/EMG7500to a version that resolves this vulnerability.Fixed in 9.7.0.1
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and hold the services permission. They can exploit the issue through the device terminal or CLI interface using the set script schedule command.
What is the practical impact of successful exploitation?
Injected commands run as root on the affected device, allowing complete compromise of its confidentiality, integrity, and availability. Downstream devices attached through serial connections may also be affected.
Which affected products have a stated fixed firmware version?
SLC8000 is affected before firmware v9.7.0.3, while EMG8500 and EMG7500 are affected before firmware v9.7.0.1. All firmware versions of SLB882, SLCx-03, and SLCx-02 are listed as affected, with no fixed version stated.
What can be done while a firmware update is unavailable?
Restrict services permission to only trusted administrators and limit their access to the terminal and CLI interfaces. Because exploitation requires an authenticated account with that permission, reviewing and reducing those assignments can reduce exposure.