Impact
The vulnerability is an undocumented command injection in the mfc eeprom read command that forwards unsanitized user input to a system() call. Any authenticated user to the terminal or CLI can use this flaw to execute arbitrary shell commands as root, causing complete loss of confidentiality, integrity and availability on the device. The impact extends to any downstream serial‑attached devices that rely on the compromised host.
Affected Systems
Affected devices include Lantronix EMG7500 and EMG8500 with firmware versions prior to 9.7.0.1, the SLC8000 with firmware earlier than 9.7.0.2, and all firmware releases of SLB882, SLCx‑02 and SLCx‑03.
Risk and Exploitability
The CVSS score of 9.4 indicates a high‑severity exploit potential. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate to the device’s terminal or CLI interface, which can be done by any user and may be exposed over a network. Once authenticated, exploitation is straightforward because the unsanitized parameter is passed directly to the shell, enabling unrestricted command execution.
OpenCVE Enrichment