CVE-2026-80154
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LANTRONIX | SLC8000 | * | affected |
| LANTRONIX | EMG8500 | * | affected |
| LANTRONIX | EMG7500 | * | affected |
| LANTRONIX | SLB882 | * | affected |
| LANTRONIX | SLCx-03 | * | affected |
| LANTRONIX | SLCx-02 | * | affected |
Weaknesses
- CWE-330: Use of Insufficiently Random Values
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://revrb.net/2026/09/21/revrb-lantern.html
- https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-predictable-session-token-with-validation-bypass
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.