CVE-2026-80149
Affected Products
Overview
An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force a server-side request forgery that causes the affected device to create SSH connections to attacker-defined endpoints. An attacker could use this capability to enumerate and/or communicate with endpoints they otherwise would not have access to.
SLC8000
This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.5R2 or later.
EMG8500
This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.1R2 or later.
EMG7500
This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.1R2 or later.
Support
For technical assistance or questions regarding this advisory, please contact [email protected].
Revision History
| Version | Date | Status | Description |
|---|---|---|---|
| 1.0 | September 21, 2026 | Fixed | New Firmware Available |







