Impact
An authenticated attacker with the services permission can exploit a command injection flaw in the set nfs download command, which passes user input directly to a system() call without sanitization. This allows the attacker to execute arbitrary shell commands with root privileges, leading to a complete compromise of confidentiality, integrity, and availability on the device and potentially affecting any downstream serial‐attached equipment.
Affected Systems
Affected are Lantronix SLC8000 devices running firmware versions prior to 9.7.0.3, EMG8500 and EMG7500 devices with firmware before 9.7.0.1, and all firmware releases of SLB882, SLCx‑03 and SLCx‑02.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.4, indicating critical severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires authenticated access with services permission, so the likely vector is an insider or privileged user compromising the terminal or CLI interface to inject malicious commands.
OpenCVE Enrichment