Authentication Bypass Vulnerability in Lantronix SLC8000 and EMG Series
CVE-2026-80155

10CRITICAL

Key Information:

Vendor

Lantronix

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-80155?

An authentication bypass vulnerability exists in the web management portal of Lantronix products, allowing unauthenticated attackers to read sensitive configuration files and upload files to arbitrary filesystem locations. This exploit is facilitated by the vulnerable handling of session cookie paths, which allows attackers to conduct path traversal attacks. By manipulating cookie values, attackers can bypass session checks and potentially compromise the confidentiality, integrity, and availability of the affected devices, posing risks to downstream connected systems.

Affected Version(s)

EMG7500 0 < 9.7.0.1

EMG8500 0 < 9.7.0.1

SLB882 *

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

RE/VRb
.