Stack-Based Buffer Overflow in Lantronix SLC8000 and EMG Series Devices
CVE-2026-80146
9.4CRITICAL
Key Information:
What is CVE-2026-80146?
The vulnerability affects multiple Lantronix devices, including the SLC8000 and EMG series, where authenticated attackers can exploit a stack-based buffer overflow by using an undocumented mfc eeprom read command. This command allows for unbounded user input to be copied into a limited stack buffer, which can lead to arbitrary code execution upon triggering the overflow. Such exploitation compromises the confidentiality, integrity, and availability of the affected device, potentially affecting any serial-attached devices downstream.
Affected Version(s)
EMG7500 0 < 9.7.0.1
EMG8500 0 < 9.7.0.1
SLB882 *
