Impact
A stack-based buffer overflow occurs when an authenticated user issues an undocumented mfc eeprom read command to the device’s terminal or CLI. The command copies unbounded user input into a fixed-size buffer on the stack before passing it to a system() call. This allows an attacker to overflow the stack, overwrite the return address, and execute arbitrary code, potentially compromising the device’s confidentiality, integrity, and availability and affecting any serial‑attached peripherals. The flaw aligns with CWE‑121.
Affected Systems
Affected models include LANTRONIX EMG7500 and EMG8500 devices running firmware versions earlier than 9.7.0.1, all versions of the SLB882, SLCx‑02, and SLCx‑03 series, and SLC8000 devices using firmware prior to 9.7.0.2. Firmware updates published by Lantronix for these families address the overflow.
Risk and Exploitability
The CVSS score is 9.4, marking the issue as critical. EPSS data is not available and the vulnerability has not yet appeared in the CISA KEV catalog. Attack requires authenticated access through the device’s terminal or CLI interface, meaning it is an authenticated local or remote network attack depending on management connectivity. When exploited, the attacker can achieve full control over the affected device and any downstream serial‑attached equipment.
OpenCVE Enrichment