CVE-2026-80152

Severity: Critical
Publish Date: September 21, 2026
Last Updated: September 21, 2026

Overview

An attacker that can authenticate as any user with the ‘services’ permission to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.

 

SLC9000

This CVE is addressed by firmware release v9.7.0.2R1 published on September 18, 2026.

Recommended Actions

 

SLC8000

This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.

Recommended Actions

 

EMG8500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

EMG7500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

 

Support

For technical assistance or questions regarding this advisory, please contact [email protected].

Revision History

Version Date Status Description
1.0 September 21, 2026 Fixed New Firmware Available