Description
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish SSH connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the SSH terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Published: 2026-09-22
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Remote Network Access via Server‑Side Request Forgery
Action: Immediate Patching
AI Analysis

Impact

Lantronix devices expose a server‑side request forgery in the WebSSH/WebTelnet listener that lets unauthenticated attackers change the rooturl parameter and force the device to open outbound SSH connections to attacker‑controlled hosts. This permits an attacker to connect into otherwise unreachable internal endpoints, enabling network reconnaissance or lateral movement, and potentially compromising systems beyond the device itself.

Affected Systems

The vulnerability affects LANTRONIX EMG7500, EMG8500, SLC8000, and SLB882. Firmware versions before 9.7.0.1 on EMG7500/EMG8500, before 9.7.0.3 on SLC8000, and all firmware versions of SLB882 are impacted.

Risk and Exploitability

The CVSS base score of 7.7 indicates a high severity attack. Because the rooturl parameter is accepted without authentication or validation, an attacker can send a crafted HTTP request to the WebSSH interface from a host within the same network, triggering the device to initiate an outbound SSH connection to any IP chosen by the attacker. Although no EPSS score is available and the vulnerability is not listed in CISA KEV, the lack of authentication combined with the ability to reach arbitrary internal hosts makes exploitation likely for an attacker who has network access to the device. This can lead to internal network penetration and potential compromise of downstream targets.

Generated by OpenCVE AI on September 22, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware updates for the affected devices (SLC8000 to v9.7.0.3R3, EMG7500/EMG8500 to v9.7.0.1R2).
  • If an update cannot be applied immediately, restrict or disable the WebSSH/WebTelnet interface to authorized management hosts only, or block the rooturl parameter by firewall ACLs to prevent unintended outbound SSH connections.
  • Monitor outbound SSH traffic from the devices and block any unexpected destinations to mitigate potential misuse before a patch is available.

Generated by OpenCVE AI on September 22, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish SSH connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the SSH terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Title Lantronix Autonomous Out-of-Band Devices WebSSH SSRF via rooturl Parameter
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T15:42:08.210Z

Reserved: 2026-08-25T20:43:54.261Z

Link: CVE-2026-80149

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T16:18:01.160

Modified: 2026-09-22T16:18:01.160

Link: CVE-2026-80149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T16:30:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)