Authentication Bypass Vulnerability in Lantronix Out-of-Band Management Devices
CVE-2026-80154
8.9HIGH
Key Information:
What is CVE-2026-80154?
An authentication bypass vulnerability exists in the web management portal of various Lantronix devices, including the SLC8000 series, allowing unauthorized attackers to derive session tokens from logged-in users. This exploitation occurs due to predictable generation of session tokens based on the device model and current time, creating a limited set of possible tokens. Invoking a specially crafted URI enables attackers to bypass IP address and User-Agent validation, granting them unauthorized access. This vulnerability could lead to elevated privileges on the impacted devices and potentially compromise connected downstream serial-attached devices.
Affected Version(s)
EMG7500 *
EMG8500 *
SLB882 *
