Command Injection Vulnerability in Lantronix SLC8000 and EMG Series Devices
CVE-2026-80152
9.4CRITICAL
Key Information:
What is CVE-2026-80152?
The command injection vulnerability present in Lantronix SLC8000 and EMG Series devices allows authenticated attackers with services permissions to execute arbitrary shell commands as root. By exploiting unsanitized input in the set script schedule command, attackers can gain complete control over the device, resulting in significant breaches of confidentiality, integrity, and availability. This flaw can also impact associated serial-attached devices, underscoring the urgency for users to update to the latest firmware versions to mitigate risks effectively.
Affected Version(s)
EMG7500 0 < 9.7.0.1
EMG8500 0 < 9.7.0.1
SLB882 *
