Authentication Bypass Vulnerability in Lantronix SLC8000 and EMG Series
CVE-2026-80155
10CRITICAL
Key Information:
What is CVE-2026-80155?
An authentication bypass vulnerability exists in the web management portal of Lantronix products, allowing unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations. This exploit is facilitated by the vulnerable handling of session cookie paths, which allows attackers to conduct path traversal attacks. By manipulating cookie values, attackers can bypass session checks and potentially compromise the confidentiality, integrity, and availability of the affected devices, posing risks to downstream connected systems.
Affected Version(s)
EMG7500 0 < 9.7.0.1
EMG8500 0 < 9.7.0.1
SLB882 *
