Description
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish Telnet connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the Telnet terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Published: 2026-09-22
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Server‑Side Request Forgery
Action: Patch Update
AI Analysis

Impact

The affected Lantronix devices expose a server‑side request forgery through the WebSSH/WebTelnet interface. By manipulating the rooturl parameter, an unauthenticated attacker can cause the device to open Telnet connections to arbitrary hosts. This allows the adversary to discover or communicate with internal network endpoints that would otherwise be unreachable, potentially facilitating further compromise.

Affected Systems

Lantronix EMG7500 and EMG8500 prior to firmware v9.7.0.1, SLC8000 prior to firmware v9.7.0.3, and all firmware revisions of SLB882 contain this weakness.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity. While EPSS data are unavailable, the lack of a KEV listing suggests no public exploits are yet reported, but the vulnerability can be exploited over the network with no authentication. The attack vector is inferred to be remote, via the publicly reachable web interface.

Generated by OpenCVE AI on September 22, 2026 at 16:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware releases (EMG7500/EMG8500 at least v9.7.0.1R2, SLC8000 at least v9.7.0.3R3, or newer) to remove the rooturl SSRF flaw.
  • If a patch cannot be applied immediately, disable the WebTelnet/WebSSH listener or block its traffic through the device configuration or associated firewall rules.
  • Limit access to the device’s web interface to trusted management hosts by implementing access control lists or firewall filtering so that only authorized IP addresses can reach the vulnerable service.

Generated by OpenCVE AI on September 22, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish Telnet connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the Telnet terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Title Lantronix Autonomous Out-of-Band Devices WebTelnet SSRF via rooturl Parameter
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T15:21:22.223Z

Reserved: 2026-08-25T20:43:54.261Z

Link: CVE-2026-80150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T16:18:01.313

Modified: 2026-09-22T16:18:01.313

Link: CVE-2026-80150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T17:00:12Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)