Impact
The vulnerability allows an attacker who has authenticated with services permission to inject arbitrary shell commands into the set cifs password command, which passes unsanitized input to a system() call. This results in execution of arbitrary commands with root privileges, leading to total loss of confidentiality, integrity, and availability on the device.
Affected Systems
LANTRONIX EMG7500 and EMG8500 devices running firmware versions earlier than 9.7.0.1, LANTRONIX SLC8000 devices before firmware 9.7.0.2, and all firmware releases of LANTRONIX SLB882, SLCx-02, and SLCx-03. The affected products are EMG7500, EMG8500, SLC8000, SLB882, SLCx-02, and SLCx-03.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. Exploitation requires only that the attacker gain a services-level account, which can be obtained by authenticating to the CLI or terminal interface. With the services permission it is trivial to enter the malicious payload. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, but the high CVSS suggests a likely impact if patched firmware is not deployed.
OpenCVE Enrichment