Impact
The vulnerability arises when the web configuration server uses snprintf to build the session cookie file path. By submitting a cookie value of a specific length, an attacker forces the buffer to truncate at the delimiter, enabling path traversal. This bypasses authentication checks, lets the attacker read sensitive configuration files, upload arbitrary files to any filesystem location, and ultimately execute code on the device. The flaw is a classic path traversal issue identified as CWE‑22.
Affected Systems
Affecting Lantronix SLC8000 firmware versions earlier than 9.7.0.5, EMG8500 and EMG7500 firmware earlier than 9.7.0.1, and all firmware releases of SLB882, SLCx‑03, and SLCx‑02, which are autonomous out‑of‑band devices that provide serial‑to‑network interfaces.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating critical severity, and is not listed in the CISA KEV catalog. EPSS is not available, so the exploitation probability is unknown, yet the lack of authentication and reliance on web access create a wide attack surface. An unauthenticated attacker with web‑portal access can exploit the path traversal, upload malicious content, and achieve remote code execution. The ability to read configuration files also enables a full compromise of the device and potentially downstream serial‑connected systems.
OpenCVE Enrichment