CVE-2026-80156

Severity: Critical
Publish Date: September 21, 2026
Last Updated: September 21, 2026

Overview

An attacker that can authenticate to the upload endpoint of the web management portal of Lantronix Autonomous Out-of-Band devices can write arbitrary data to any location on that device’s disk, leading to remote code execution and the ability to impact downstream serial-connected devices.

 

SLC9000

This CVE is addressed by firmware release v9.7.0.2R1 published on September 18, 2026.

Recommended Actions

 

SLC8000

This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.

Recommended Actions

 

EMG8500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

EMG7500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

 

Support

For technical assistance or questions regarding this advisory, please contact [email protected].

Revision History

Version Date Status Description
1.0 September 21, 2026 Fixed New Firmware Available