PT-2026-96809 · Lantronix · Sc8000+6

·

CVE-2026-80154

·

Published

2026-09-22

·

Updated

2026-09-24

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lantronix SLC8000 (affected versions not specified) Lantronix SLC9000 (affected versions not specified) Lantronix EMG8500 (affected versions not specified) Lantronix EMG7500 (affected versions not specified) Lantronix SLB882 (affected versions not specified) Lantronix SLCx-03 (affected versions not specified) Lantronix SLCx-02 (affected versions not specified)
Description An authentication bypass exists in the web management portal. Unauthenticated attackers can derive valid session tokens of logged-in users because tokens are generated deterministically based on the device model and the current time at one-second resolution. This creates a small enumerable set of possible active tokens. By constructing a crafted URI that exploits file extension handling in the web server path routing, attackers can bypass source IP and User-Agent validation. This allows the use of a derived token from a different source address to gain elevated privileges on the device and potentially impact downstream serial-attached devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80154

Affected Products

Emg7500
Emg8500
Slb882
Sc8000
Slc9000
Slcx-02
Slcx-03