CVE-2026-80150

Severity: High
Publish Date: September 21, 2026
Last Updated: September 21, 2026

Overview

An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force a server-side request forgery that causes the affected device to create telnet connections to attacker-defined endpoints. An attacker could use this capability to enumerate and/or communicate with endpoints they otherwise would not have access to.

 

SLC8000

This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.

Recommended Actions

 

EMG8500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

EMG7500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

 

Support

For technical assistance or questions regarding this advisory, please contact [email protected].

Revision History

Version Date Status Description
1.0 September 21, 2026 Fixed New Firmware Available