CVE-2026-80155

Severity: Critical
Publish Date: September 21, 2026
Last Updated: September 21, 2026

Overview

An unauthenticated attacker that can access the web management portal on Lantronix Autonomous Out-of-Band devices can bypass authentication checks to pull key configuration files (such as usernames and hashed passwords) and upload files to key filesystem locations, leading to remote code execution and the ability to impact downstream serial-connected devices.

 

SLC9000

This CVE is addressed by firmware release v9.7.0.2R1 published on September 18, 2026.

Recommended Actions

 

SLC8000

This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.

Recommended Actions

 

EMG8500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

EMG7500

This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.

Recommended Actions

 

Support

For technical assistance or questions regarding this advisory, please contact [email protected].

Revision History

Version Date Status Description
1.0 September 21, 2026 Fixed New Firmware Available