{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/slcx-02--9.7.0.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-80143"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SLC8000 (\u003c 9.7.0.2)","EMG8500 (\u003c 9.7.0.1)","EMG7500 (\u003c 9.7.0.1)","SLB882 (\u003c 9.7.0.2)","SLCx-03 (\u003c 9.7.0.2)","SLCx-02 (\u003c 9.7.0.2)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-80143","command-injection","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["Lantronix"],"content_html":"\u003cp\u003eLantronix console managers including the SLC8000 (versions before 9.7.0.2), EMG8500 and EMG7500 (versions before 9.7.0.1), and all versions of the SLB882, SLCx-03, and SLCx-02 contain a critical command injection vulnerability (CVE-2026-80143). This vulnerability stems from an undocumented MFC EEPROM read command that fails to sanitize user-supplied input before passing it to a system call. An authenticated attacker, regardless of their privilege level, can leverage this flaw to execute arbitrary commands with root privileges. Given the nature of these devices as console managers, successful exploitation provides total control over the appliance and potentially facilitates unauthorized access to downstream serial-attached infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full loss of confidentiality, integrity, and availability of the targeted console manager. Because these devices manage serial connections to other networking hardware, an attacker could pivot or conduct lateral movement into the serial-attached environment. The vulnerability impacts enterprise infrastructure management, posing a severe risk to data center availability and administrative control over managed assets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate patching of vulnerable Lantronix console managers.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade SLC8000 devices to firmware v9.7.0.2 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade EMG8500 and EMG7500 devices to firmware v9.7.0.1 or later.\u003c/li\u003e\n\u003cli\u003eFor legacy or unsupported models (SLB882, SLCx-03, SLCx-02) where patches may not be available, restrict management interface access to highly controlled jump hosts and disable the terminal or CLI interface for non-administrative users.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-22T16:37:22Z","date_published":"2026-09-22T16:37:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lantronix-command-injection/","summary":"Authenticated attackers can execute arbitrary shell commands as root on multiple Lantronix console manager models by exploiting an undocumented MFC EEPROM read command that triggers command injection via a system call.","title":"Command Injection in Lantronix Console Managers (CVE-2026-80143)","url":"https://feed.craftedsignal.io/briefs/2026-09-lantronix-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - SLCx-02 (\u003c 9.7.0.2)","version":"https://jsonfeed.org/version/1.1"}