Authentication Bypass Vulnerability in Lantronix Out-of-Band Management Devices
CVE-2026-80154

8.9HIGH

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80154?

An authentication bypass vulnerability exists in the web management portal of various Lantronix devices, including the SLC8000 series, allowing unauthorized attackers to derive session tokens from logged-in users. This exploitation occurs due to predictable generation of session tokens based on the device model and current time, creating a limited set of possible tokens. Invoking a specially crafted URI enables attackers to bypass IP address and User-Agent validation, granting them unauthorized access. This vulnerability could lead to elevated privileges on the impacted devices and potentially compromise connected downstream serial-attached devices.

Affected Version(s)

EMG7500 *

EMG8500 *

SLB882 *

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.