Impact
Lantronix devices are vulnerable to a path traversal flaw that allows an authenticated attacker to write arbitrary data to any location on the device’s filesystem through the web management portal upload endpoint, resulting in remote code execution and complete loss of confidentiality, integrity, and availability.
Affected Systems
Affected vendors and products include Lantronix EMG7500, EMG8500, SLB882, SLC8000, SLCx-02, and SLCx-03. Firmware versions prior to 9.7.0.5 on the SLC8000, prior to 9.7.0.1 on the EMG7500 and EMG8500, and all firmware versions of the SLB882, SLCx-02, and SLCx-03 are vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attack requires authentication to the web management portal; a malicious file name that mixes backslash and forward slash characters bypasses filename validation, enabling an attacker to write arbitrary files to any writable location, which can be leveraged to execute code on the device.
OpenCVE Enrichment