<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SLCx-02 (&lt; 9.7.0.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/slcx-02--9.7.0.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 16:37:22 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/slcx-02--9.7.0.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in Lantronix Console Managers (CVE-2026-80143)</title><link>https://feed.craftedsignal.io/briefs/2026-09-lantronix-command-injection/</link><pubDate>Tue, 22 Sep 2026 16:37:22 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-lantronix-command-injection/</guid><description>Authenticated attackers can execute arbitrary shell commands as root on multiple Lantronix console manager models by exploiting an undocumented MFC EEPROM read command that triggers command injection via a system call.</description><content:encoded><![CDATA[<p>Lantronix console managers including the SLC8000 (versions before 9.7.0.2), EMG8500 and EMG7500 (versions before 9.7.0.1), and all versions of the SLB882, SLCx-03, and SLCx-02 contain a critical command injection vulnerability (CVE-2026-80143). This vulnerability stems from an undocumented MFC EEPROM read command that fails to sanitize user-supplied input before passing it to a system call. An authenticated attacker, regardless of their privilege level, can leverage this flaw to execute arbitrary commands with root privileges. Given the nature of these devices as console managers, successful exploitation provides total control over the appliance and potentially facilitates unauthorized access to downstream serial-attached infrastructure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full loss of confidentiality, integrity, and availability of the targeted console manager. Because these devices manage serial connections to other networking hardware, an attacker could pivot or conduct lateral movement into the serial-attached environment. The vulnerability impacts enterprise infrastructure management, posing a severe risk to data center availability and administrative control over managed assets.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate patching of vulnerable Lantronix console managers.</p>
<ul>
<li>Upgrade SLC8000 devices to firmware v9.7.0.2 or later.</li>
<li>Upgrade EMG8500 and EMG7500 devices to firmware v9.7.0.1 or later.</li>
<li>For legacy or unsupported models (SLB882, SLCx-03, SLCx-02) where patches may not be available, restrict management interface access to highly controlled jump hosts and disable the terminal or CLI interface for non-administrative users.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve-2026-80143</category><category>command-injection</category><category>network-infrastructure</category></item></channel></rss>