CVE-2026-80156
Affected Products
Overview
An attacker that can authenticate to the upload endpoint of the web management portal of Lantronix Autonomous Out-of-Band devices can write arbitrary data to any location on that device’s disk, leading to remote code execution and the ability to impact downstream serial-connected devices.
SLC9000
This CVE is addressed by firmware release v9.7.0.2R1 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.2R1 or later.
SLC8000
This CVE is addressed by firmware release v9.7.0.5R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.5R2 or later.
EMG8500
This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.1R2 or later.
EMG7500
This CVE is addressed by firmware release v9.7.0.1R2 published on September 18, 2026.
Recommended Actions
- Upgrade to firmware version v9.7.0.1R2 or later.
Support
For technical assistance or questions regarding this advisory, please contact [email protected].
Revision History
| Version | Date | Status | Description |
|---|---|---|---|
| 1.0 | September 21, 2026 | Fixed | New Firmware Available |







