External risk intelligence

Lantronix Command Injection Vulnerability Affects SLC and EMG Devices

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-80145

The affected products are Out-of-Band management devices and console servers. These devices are commonly deployed as network appliances to provide remote access and management to infrastructure, making them frequent candidates for internet-facing or edge-service deployment in data center and network management environments.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects Lantronix devices used for remote access and management, potentially allowing authenticated attackers to execute arbitrary commands with full control. This could lead to a complete loss of confidentiality, integrity, and availability for the device and any connected systems.

  • Command injection in management devices.
  • High impact on critical infrastructure access.
  • Confirm device relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with services permission can authenticate to a Lantronix device's terminal or CLI interface and exploit a vulnerability in the `set cifs password` command. This command passes unsanitized user input to a system function, allowing the attacker to execute arbitrary shell commands as the root user. This can lead to a complete loss of confidentiality, integrity, and availability for the device and potentially affect connected downstream devices.

  • Authenticated access required.
  • Unsanitized input to command.
  • Full device compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an authenticated attacker with services permissions to execute arbitrary commands on the affected Lantronix devices. This could lead to a complete loss of confidentiality, integrity, and availability of the device and potentially impact connected serial devices when the "set cifs password" command is exploited with unsanitized user input.

  • Device command execution and data access.
  • Exploiting the "set cifs password" command.
  • Complete loss of device confidentiality and integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

The operational technology (OT) and infrastructure teams are likely responsible for managing these Lantronix devices. The first practical step is to identify all instances of the affected hardware, confirm their accessibility and criticality, and then assign ownership for remediation planning.

  • Own by infrastructure and OT teams.
  • Verify device reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What are Lantronix SLC and EMG devices used for?

These devices function as Out-of-Band management consoles and network appliances. Organizations deploy them to provide remote, administrative access to critical infrastructure, such as servers and network hardware, ensuring connectivity even when primary network paths fail.

How does this CVE-2026-80145 command injection occur?

The flaw involves Improper Neutralization of Special Elements used in an OS Command (CWE-78). Specifically, the device fails to sanitize user input provided to the 'set cifs password' command. Because this input is passed directly to a system function, the underlying operating system executes it as root.

Do I need to be a system administrator to trigger this bug?

Yes. This vulnerability is not accessible to unauthenticated users. It specifically requires an attacker to already possess 'services' level permissions. Once authenticated to the CLI or terminal interface, they can manipulate the vulnerable command parameter.

Is my device at risk if it is not on the internet?

Halo Surface Signal indicates these devices are frequently placed at the edge of networks or exposed to the internet to facilitate remote management. If your device is internet-facing, it faces higher risk; however, even internal devices are vulnerable if an attacker gains the required 'services' account access.

How should I respond to this Lantronix advisory?

Begin by auditing your infrastructure to locate all affected SLC8000, SLC9000, EMG7500, and EMG8500 models. Verify their current firmware version and network placement. Coordinate with your IT and OT teams to prioritize remediation for units with the highest exposure or those managing the most critical downstream serial-attached systems.

References