Server-side Request Forgery Vulnerability in Lantronix Products
CVE-2026-80148

7.7HIGH

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80148?

The affected Lantronix products exhibit a server-side request forgery vulnerability within the WebSSH/WebTelnet listener. This flaw enables unauthenticated attackers to manipulate the SSH connection process and redirect connections to malicious endpoints. By exploiting an overlong username input via the shellinaboxd component, an attacker can truncate the device's IP suffix, allowing them to establish unauthorized communication with otherwise unreachable internal network services. This vulnerability poses significant risks to network security, as attackers could potentially enumerate sensitive endpoints or gain access to internal resources.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.