Command Injection Vulnerability in Lantronix SLC8000 and EMG Series Products
CVE-2026-80144
9.4CRITICAL
Key Information:
What is CVE-2026-80144?
The Lantronix SLC8000, EMG8500, EMG7500, and other related devices contain a command injection flaw due to an undocumented mfc eeprom write command. This vulnerability allows authenticated users to execute arbitrary shell commands with root privileges by injecting malicious input through unsanitized parameters in the CLI interface. As a result, attackers can compromise the device's confidentiality, integrity, and availability, potentially affecting connected serial devices as well.
Affected Version(s)
EMG7500 0 < 9.7.0.1
EMG8500 0 < 9.7.0.1
SLB882 *
