Server-Side Request Forgery in Lantronix SLC8000 and EMG Series Products
CVE-2026-80149

7.7HIGH

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80149?

A server-side request forgery vulnerability exists in the WebSSH/WebTelnet listener of Lantronix devices, allowing unauthenticated attackers to manipulate the system into making SSH connections to malicious servers. By exploiting the rooturl parameter, attackers can redirect the SSH terminal connection to any chosen host or IP address, enabling them to communicate with or enumerate internal network resources that would usually remain protected from such access. This vulnerability poses significant risks as it can expose sensitive data and internal network structures.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.