CVE-2026-80154
Lantronix Autonomous Out-of-Band Devices Predictable Session Token with Validation Bypass
All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.
| CWE | CWE-330 |
| Vendor | lantronix |
| Product | slc8000 |
| Published | Sep 22, 2026 |
Get instant alerts for lantronix slc8000
Be the first to know when new critical vulnerabilities affecting lantronix slc8000 are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H