CVE-2026-80154 PUBLISHED

Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass

Assigner: VulnCheck
Reserved: 25.08.2026 Published: 22.09.2026 Updated: 22.09.2026

All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 8.9

Product Status

Vendor LANTRONIX
Product SLC8000
Versions Default: unknown
  • Version * is affected
Vendor LANTRONIX
Product EMG8500
Versions Default: unknown
  • Version * is affected
Vendor LANTRONIX
Product EMG7500
Versions Default: unknown
  • Version * is affected
Vendor LANTRONIX
Product SLB882
Versions Default: unknown
  • Version * is affected
Vendor LANTRONIX
Product SLCx-03
Versions Default: unknown
  • Version * is affected
Vendor LANTRONIX
Product SLCx-02
Versions Default: unaffected
  • Version * is affected

Credits

  • RE/VRb finder

References

Problem Types

  • Use of Insufficiently Random Values CWE