Impact
The vulnerability is a command injection flaw in an undocumented mfc eeprom write command that passes unsanitized user input to a system() call. An authenticated attacker with access to the terminal or CLI interface can supply crafted input that is executed with root privileges. This results in complete loss of confidentiality, integrity, and availability on the affected device and may affect devices connected downstream via serial interfaces.
Affected Systems
LANTRONIX routers and devices including EMG7500, EMG8500, SLB882, SLC8000, SLCx-02, and SLCx-03. Firmware versions before v9.7.0.2 on SLC8000, before v9.7.0.1 on the EMG series, and all versions of SLB882, SLCx-02, and SLCx-03 are impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity. The EPSS score is not reported, and this issue is not listed in CISA's KEV catalog. Attackers must first authenticate to the device using the CLI or terminal interface; the vulnerability is exercised through the machine's command shell. Once authenticated, the attacker can inject any shell command, leading to full system compromise.
OpenCVE Enrichment