Server-Side Request Forgery Vulnerability in Lantronix Devices
CVE-2026-80150

7.7HIGH

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80150?

A server-side request forgery vulnerability exists in the WebSSH/WebTelnet listener of specific Lantronix devices, allowing unauthenticated attackers to exploit the system. By manipulating the rooturl parameter, an attacker can redirect Telnet connections initiated by the affected device to arbitrary IP addresses or hosts. This capability enables attackers to bypass network constraints and communicate with internal endpoints that are typically protected from direct access. The potential for network enumeration and unauthorized command execution raises significant security concerns for users of these devices.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.