CVE-2026-80154
Received Received - Intake

Authentication Bypass in Lantronix SLC8000 Series Firmware

Vulnerability report for CVE-2026-80154, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: VulnCheck

Description

All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
lantronix slc8000 *
lantronix emg8500 *
lantronix emg7500 *
lantronix slb882 *
lantronix slcx-03 *
lantronix slcx-02 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-330 The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authentication bypass in Lantronix devices that allows unauthenticated attackers to generate valid session tokens for logged-in users. Tokens are created using the device model and current time, making them predictable. Attackers can bypass IP and User-Agent checks by crafting a specific URI that exploits file extension handling in the web server.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized access attempts or unusual session activity in the web management portal of affected Lantronix devices. Monitor logs for repeated failed login attempts or unexpected session token usage. Since tokens are derived from device model and time, inspect network traffic for crafted URIs exploiting file extension handling. Use network scanning tools to identify vulnerable devices by checking firmware versions.

Impact Analysis

An attacker could gain elevated privileges on the device, bypass security controls, and potentially access or control downstream serial-attached devices. This could lead to unauthorized configuration changes, data theft, or disruption of connected systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may fail compliance audits if they cannot demonstrate adequate protection against such attacks.

Mitigation Strategies

Immediately isolate affected devices from untrusted networks. Disable the web management portal if not essential. Apply firmware updates from Lantronix if available. Implement network-level access controls to restrict access to the management interface. Monitor for suspicious activity and revoke any unauthorized sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80154. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart