Impact
Lantronix devices expose a server‑side request forgery in the WebSSH/WebTelnet listener that lets unauthenticated attackers change the rooturl parameter and force the device to open outbound SSH connections to attacker‑controlled hosts. This permits an attacker to connect into otherwise unreachable internal endpoints, enabling network reconnaissance or lateral movement, and potentially compromising systems beyond the device itself.
Affected Systems
The vulnerability affects LANTRONIX EMG7500, EMG8500, SLC8000, and SLB882. Firmware versions before 9.7.0.1 on EMG7500/EMG8500, before 9.7.0.3 on SLC8000, and all firmware versions of SLB882 are impacted.
Risk and Exploitability
The CVSS base score of 7.7 indicates a high severity attack. Because the rooturl parameter is accepted without authentication or validation, an attacker can send a crafted HTTP request to the WebSSH interface from a host within the same network, triggering the device to initiate an outbound SSH connection to any IP chosen by the attacker. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the lack of authentication combined with the ability to reach arbitrary internal hosts makes exploitation likely for an attacker who has network access to the device. This can lead to internal network penetration and potential compromise of downstream targets.
OpenCVE Enrichment