Command Injection Vulnerability in Lantronix SLC8000 and EMG Series Devices
CVE-2026-80152

9.4CRITICAL

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80152?

The command injection vulnerability present in Lantronix SLC8000 and EMG Series devices allows authenticated attackers with services permissions to execute arbitrary shell commands as root. By exploiting unsanitized input in the set script schedule command, attackers can gain complete control over the device, resulting in significant breaches of confidentiality, integrity, and availability. This flaw can also impact associated serial-attached devices, underscoring the urgency for users to update to the latest firmware versions to mitigate risks effectively.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.