External risk intelligence

Lantronix Path Traversal Leading to Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-80156

The vulnerability affects management portals on infrastructure appliances (console servers and out-of-band management devices). These devices are commonly deployed as network-accessible management gateways, making their web interfaces reachable in many deployment environments, even if intended for internal use.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts Lantronix devices used for serial device management, allowing authenticated users to gain control of the device and potentially other connected equipment. The concern lies in the potential for unauthorized access and disruption to critical infrastructure management.

  • Attackers can take over management devices.
  • Critical infrastructure management could be compromised.
  • Confirm relevance and exposure to protect operations.

Attack Path

How an attacker could exploit the issue

An attacker with existing administrative access to the web management portal could exploit this vulnerability. By manipulating upload filenames, they can write arbitrary data to any location on the device, potentially leading to code execution and full system compromise.

  • Authenticated administrative access required.
  • Upload filename manipulation bypasses validation.
  • Arbitrary file write can lead to code execution.

Live Threat

Current exploitation, exposure, and threat context

Authenticated attackers could write arbitrary data to any location on the device's filesystem, potentially leading to remote code execution, loss of confidentiality, integrity, and availability. This could also impact downstream serial-connected devices.

  • Device filesystem and configuration.
  • Arbitrary file write via web portal upload.
  • Complete loss of device and service availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Lantronix devices mentioned are typically managed by infrastructure or network operations teams, with potential involvement from security teams for exposure assessment. The initial practical step is to inventory these devices, determine their network accessibility, and identify business-critical systems they manage to prioritize remediation.

  • Identify device ownership and scope.
  • Verify network exposure and impact.
  • Plan coordinated firmware updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Lantronix equipment affected by CVE-2026-80156?

These products, including SLC8000, SLC9000, and EMG series devices, are out-of-band management appliances. They act as centralized hubs for IT professionals to remotely access, monitor, and troubleshoot serial-connected equipment like routers, switches, and servers when primary network connectivity fails.

How does this path traversal vulnerability work?

Classified as CWE-22, this flaw exists in the web portal's file upload process. The system attempts to sanitize filenames by stripping backslashes, but it fails to inspect for forward slashes afterward. An attacker can use a specially crafted filename to bypass these checks, allowing them to save files outside the designated upload folder and overwrite critical system files.

Do I need to be logged in to trigger this bug?

Yes. An attacker must have established administrative access to the web management portal to perform the malicious file upload. Simply navigating to the login page without valid credentials will not trigger this vulnerability.

How does Halo Surface Signal categorize this threat?

Halo Surface Signal labels this as likely relevant because these management gateways are often network-accessible. While intended for internal use, their role as critical infrastructure bridges often results in deployments where the management interface is reachable over the network, increasing the risk of unauthorized access.

What is the first step to secure these devices?

Begin by creating an inventory of your Lantronix hardware to understand your total footprint. Once identified, audit their network placement to confirm if they are reachable from untrusted segments, and prepare to coordinate firmware upgrades to the versions specified in the advisory to patch the upload mechanism.

References