Impact
The vulnerability arises from session tokens that are generated deterministically using the device model and the current time with one‑second resolution. Because tokens are predictable, an attacker can enumerate the small set of possible active tokens. By crafting a URI that leverages file extension handling in the web server path routing, the attacker can bypass source‑IP and User‑Agent validation checks, effectively authenticating as a logged‑in user without credentials. This allows unauthorized escalation to device‑level privileges, enabling control over the device, remote configuration changes, and potentially affecting serial‑attached downstream devices.
Affected Systems
All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx‑03, and SLCx‑02 are affected. Any device running these models is exposed to the token forgery and validation bypass described above.
Risk and Exploitability
The vulnerability has a CVSS score of 8.9, denoting high severity. Because it permits unauthenticated remote attackers to deduce valid session tokens, the EPSS score is currently unavailable but the risk remains significant due to the predictable token scheme and lack of network restrictions. Attackers could exploit the flaw via standard web interfaces, crafting requests to bypass authentication and gaining elevated privileges. The flaw is not listed in the CISA KEV catalog, but the potential impact warrants immediate attention.
OpenCVE Enrichment