Description
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set nfs download command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
Published: 2026-09-22
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

An authenticated attacker with the services permission can exploit a command injection flaw in the set nfs download command, which passes user input directly to a system() call without sanitization. This allows the attacker to execute arbitrary shell commands with root privileges, leading to a complete compromise of confidentiality, integrity, and availability on the device and potentially affecting any downstream serial‐attached equipment.

Affected Systems

Affected are Lantronix SLC8000 devices running firmware versions prior to 9.7.0.3, EMG8500 and EMG7500 devices with firmware before 9.7.0.1, and all firmware releases of SLB882, SLCx‑03 and SLCx‑02.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.4, indicating critical severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. The attack requires authenticated access with services permission, so the likely vector is an insider or privileged user compromising the terminal or CLI interface to inject malicious commands.

Generated by OpenCVE AI on September 22, 2026 at 16:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that removes the command injection bug
  • Restrict the services permission to only trusted administrators and audit which accounts hold that privilege
  • Monitor system logs for unexpected command executions and investigate any anomalies promptly

Generated by OpenCVE AI on September 22, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set nfs download command that passes unsanitized user input to a system() call. Attackers with the services permission can authenticate to the terminal or CLI interface and inject malicious commands through the unsanitized parameter to achieve complete loss of confidentiality, integrity, and availability on the affected device and potentially impact downstream serial-attached devices.
Title Lantronix Autonomous Out-of-Band Devices OS Command Injection via set nfs download
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-22T15:21:45.246Z

Reserved: 2026-08-25T20:43:54.261Z

Link: CVE-2026-80151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-22T16:18:01.460

Modified: 2026-09-22T16:18:01.460

Link: CVE-2026-80151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T16:45:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')