External risk intelligence

Lantronix Command Injection Vulnerability in Out-of-Band Management Devices

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-80152

The affected products are Out-of-Band (OOB) management gateways and console servers. These devices are designed to provide remote access to network infrastructure and are commonly deployed as network-edge appliances or remote access portals, making their management interfaces reachable in typical deployment scenarios.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This CVE involves a command injection vulnerability found in certain Lantronix devices, specifically those used for out-of-band management. The flaw allows authenticated attackers to execute arbitrary commands with root privileges, potentially leading to a complete compromise of the affected device and any connected systems. The main concern is to confirm if these types of devices are in use and exposed.

  • Unsanitized commands can take over management devices.
  • Critical infrastructure could be compromised remotely.
  • Assess exposure of remote management gateways.

Attack Path

How an attacker could exploit the issue

An attacker with existing authenticated access to the device's terminal or CLI can exploit this vulnerability. By leveraging the "set script schedule" command, they can pass unsanitized user input, which is then passed to a system() call. This allows the attacker to execute arbitrary shell commands as the root user, potentially leading to a complete compromise of the device and impact on connected equipment.

  • Attacker needs authenticated access.
  • Unsanitized input to schedule command.
  • Complete system compromise.

Live Threat

Current exploitation, exposure, and threat context

Authenticated attackers with services permission could execute arbitrary commands as root on the affected devices. This could lead to a complete loss of confidentiality, integrity, and availability for the device and any downstream serial-attached devices.

  • Device command execution and control.
  • Injecting commands via the set script schedule.
  • Complete device compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Infrastructure and security teams are likely responsible for addressing this command injection vulnerability, given the nature of the affected devices as out-of-band management gateways and console servers. The initial practical move involves identifying all instances of the affected Lantronix devices, confirming their network reachability and business criticality, and locating the accountable asset owner. Remediation planning should then be prioritized based on assessed risk and potential impact on downstream serial-attached devices.

  • Own by infrastructure or security teams.
  • Verify device reachability and criticality.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the role of Lantronix SLC, EMG, and SLB series devices?

These devices serve as out-of-band management gateways and console servers. They are critical infrastructure components that provide administrators with secure, remote access to network equipment, serial consoles, and power management interfaces when primary networks are unavailable or unresponsive.

How does CVE-2026-80152 function?

This vulnerability is classified as OS Command Injection (CWE-78). It occurs because the device improperly cleans user-provided input before passing it to a system command. By exploiting the 'set script schedule' command, an attacker can append their own malicious instructions, forcing the device to run them with elevated root-level permissions.

Do I need to be an admin to trigger this vulnerability?

Yes. An attacker must already have authenticated access to the device's CLI or terminal interface with the specific 'services' permission to reach the vulnerable command. Simply sending unauthorized network traffic to the device will not trigger the bug; the attacker must be a logged-in user with sufficient, though not necessarily administrative, privileges.

Why should I care about this CVE based on Halo Surface Signal?

Halo Surface Signal notes that these products are commonly deployed as network-edge appliances or remote access portals. Because these devices are specifically designed to be reachable for remote management, the management interfaces are often exposed, making it vital to confirm whether your specific instances are accessible via the internet or internal networks.

What is the first step to address this risk?

Start by performing a comprehensive inventory of your environment to identify all Lantronix SLC, EMG, and SLB devices in use. Once you have a list, verify their current firmware versions and network reachability to determine which units are exposed. Coordinate with the designated infrastructure or security asset owners to prioritize these devices for firmware updates based on their criticality.

References