Impact
The affected Lantronix devices expose a server‑side request forgery through the WebSSH/WebTelnet interface. By manipulating the rooturl parameter, an unauthenticated attacker can cause the device to open Telnet connections to arbitrary hosts. This allows the adversary to discover or communicate with internal network endpoints that would otherwise be unreachable, potentially facilitating further compromise.
Affected Systems
Lantronix EMG7500 and EMG8500 prior to firmware v9.7.0.1, SLC8000 prior to firmware v9.7.0.3, and all firmware revisions of SLB882 contain this weakness.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. While EPSS data are unavailable, the lack of a KEV listing suggests no public exploits are yet reported, but the vulnerability can be exploited over the network with no authentication. The attack vector is inferred to be remote, via the publicly reachable web interface.
OpenCVE Enrichment