Impact
A stack‑based buffer overflow exists in the mfc eeprom write command of several Lantronix devices. The command copies unbounded input into a limited stack buffer and then passes it to a system() call, allowing an authenticated attacker to execute arbitrary code. The consequence is a full compromise of confidentiality, integrity, and availability on the affected device and any serial‑attached equipment.
Affected Systems
Vendors: Lantronix. Products: EMG7500, EMG8500, SLB882, SLC8000, SLCx‑02, SLCx‑03. Versions at risk are all firmware runs before v9.7.0.2 on the SLC8000, before v9.7.0.1 on the EMG8500/EMG7500, and all firmware on the SLB882, SLCx‑03, and SLCx‑02.
Risk and Exploitability
The CVSS score of 9.4 marks the issue as critical. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack requires only authenticated access to the terminal or CLI interface and the supply of an oversized input. The attack path is relatively straightforward once credentials are obtained, so the risk of exploitation remains high in environments where the devices are remotely reachable and users can log in.
OpenCVE Enrichment