CVE-2026-80154: Lantronix EMG7500
Critical severity, CVSS 9.6. EPSS: 0.6% chance of exploitation in the next 30 days.
All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.
Affected products
- Lantronix EMG7500: any version
- Lantronix EMG8500: any version
- Lantronix SLB882: any version
- Lantronix SLC8000: any version
- Lantronix SLC9000: any version
- Lantronix Slcx-02: any version
- Lantronix Slcx-03: any version
Published 2026-09-22. Last modified 2026-09-24.