Impact
The vulnerability resides in the set script schedule command, which passes unsanitized user input directly into a system() call, enabling an attacker to execute arbitrary shell commands with root privileges. This type of flaw corresponds to the null pointer or command injection weakness identified as CWE‑78. Successful exploitation results in complete loss of confidentiality, integrity, and availability on the compromised device, and may extend to downstream serial‑attached devices connected to the device’s ports.
Affected Systems
The affected devices are LANTRONIX EMG7500 and EMG8500 running firmware versions earlier than 9.7.0.1, the SLC8000 running firmware versions earlier than 9.7.0.3, and all firmware versions of SLB882, SLCx‑02, and SLCx‑03. Users of these models should verify they are running an officially released patched firmware version that addresses this command injection flaw.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical security severity. While an EPSS score is not currently available, the flaw is not listed in the CISA KEV catalog, though the high CVSS suggests it is likely to be actively considered by threat actors. The attack requires authenticated access with services permission, typically through the terminal or CLI interface; once authenticated, an attacker can inject malicious commands. The lack of a publicly listed exploit does not preclude use, and the vulnerability remains highly exploitable to those possessing valid credentials on the device.
OpenCVE Enrichment