Skip to content
Threat Feed
critical advisory

Command Injection in Lantronix Console Managers (CVE-2026-80143)

Authenticated attackers can execute arbitrary shell commands as root on multiple Lantronix console manager models by exploiting an undocumented MFC EEPROM read command that triggers command injection via a system call.

CVE search metadata

CVE search record: CVE-2026-80143. Severity: critical. CVSS: 9.9. KEV: no. Product: SLC8000 (< 9.7.0.2), EMG8500 (< 9.7.0.1), EMG7500 (< 9.7.0.1), SLB882 (< 9.7.0.2), SLCx-03 (< 9.7.0.2), SLCx-02 (< 9.7.0.2). Brief: Command Injection in Lantronix Console Managers (CVE-2026-80143). Brief link: https://feed.craftedsignal.io/briefs/2026-09-lantronix-command-injection/

Lantronix console managers including the SLC8000 (versions before 9.7.0.2), EMG8500 and EMG7500 (versions before 9.7.0.1), and all versions of the SLB882, SLCx-03, and SLCx-02 contain a critical command injection vulnerability (CVE-2026-80143). This vulnerability stems from an undocumented MFC EEPROM read command that fails to sanitize user-supplied input before passing it to a system call. An authenticated attacker, regardless of their privilege level, can leverage this flaw to execute arbitrary commands with root privileges. Given the nature of these devices as console managers, successful exploitation provides total control over the appliance and potentially facilitates unauthorized access to downstream serial-attached infrastructure.

Impact

Successful exploitation results in full loss of confidentiality, integrity, and availability of the targeted console manager. Because these devices manage serial connections to other networking hardware, an attacker could pivot or conduct lateral movement into the serial-attached environment. The vulnerability impacts enterprise infrastructure management, posing a severe risk to data center availability and administrative control over managed assets.

Recommendation

Prioritize the immediate patching of vulnerable Lantronix console managers.

  • Upgrade SLC8000 devices to firmware v9.7.0.2 or later.
  • Upgrade EMG8500 and EMG7500 devices to firmware v9.7.0.1 or later.
  • For legacy or unsupported models (SLB882, SLCx-03, SLCx-02) where patches may not be available, restrict management interface access to highly controlled jump hosts and disable the terminal or CLI interface for non-administrative users.

Immediate actions

Inventory all Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 devices

IT Operations 24h

Mitigations

Upgrade firmware for SLC8000 to 9.7.0.2 and EMG8500/EMG7500 to 9.7.0.1

immediate IT Operations

CVE-2026-80143