Command Injection Vulnerability in Lantronix SLC8000 and EMG Series Products
CVE-2026-80144

9.4CRITICAL

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80144?

The Lantronix SLC8000, EMG8500, EMG7500, and other related devices contain a command injection flaw due to an undocumented mfc eeprom write command. This vulnerability allows authenticated users to execute arbitrary shell commands with root privileges by injecting malicious input through unsanitized parameters in the CLI interface. As a result, attackers can compromise the device's confidentiality, integrity, and availability, potentially affecting connected serial devices as well.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.