Server-Side Request Forgery Vulnerability in Lantronix Devices
CVE-2026-80150
7.7HIGH
Key Information:
What is CVE-2026-80150?
A server-side request forgery vulnerability exists in the WebSSH/WebTelnet listener of specific Lantronix devices, allowing unauthenticated attackers to exploit the system. By manipulating the rooturl parameter, an attacker can redirect Telnet connections initiated by the affected device to arbitrary IP addresses or hosts. This capability enables attackers to bypass network constraints and communicate with internal endpoints that are typically protected from direct access. The potential for network enumeration and unauthorized command execution raises significant security concerns for users of these devices.
Affected Version(s)
EMG7500 0 < 9.7.0.1
EMG8500 0 < 9.7.0.1
SLB882 *
