Impact
Lantronix devices have a server‑side request forgery vulnerability in their WebSSH/WebTelnet listener that is triggered by a truncated username input. An attacker can supply an overlong username to cause the device's shellinaboxd component to drop part of the IP suffix, thereby redirecting the outgoing SSH connection to an attacker‑controlled endpoint. This allows enumeration or communication with internal network nodes that are otherwise inaccessible, potentially giving an adversary a foothold for further lateral movement or data exfiltration.
Affected Systems
The flaw affects LANTRONIX devices including the EMG7500 and EMG8500 before firmware v9.7.0.1, the SLC8000 before firmware v9.7.0.3, and all firmware versions of the SLB882. The vulnerability exists in the WebSSH/WebTelnet listener component of each device.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity level. Although EPSS data is not available, the lack of a KEV listing does not mitigate the risk; the flaw remains exploitable wherever the management interface is reachable from an unauthenticated attacker. A likely attack path involves a network‑accessible WebSSH interface, where an attacker sends a specially crafted username to trigger the SSRF. Once exploited, the device can connect to any target host, enabling internal network discovery or further attacks. The risk is greatest in environments where these devices are exposed to untrusted networks or where outbound SSH traffic from the device is unrestricted.
OpenCVE Enrichment