{"id":"CVE-2026-80154","title":"All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…","summary":"All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-330"],"vendor":"LANTRONIX","product":"SLC8000","affected":["SLC8000","EMG8500","EMG7500","SLB882","SLCx-03","SLCx-02"],"published":"2026-09-22","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:17:31.517","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80154","references":[{"url":"https://revrb.net/2026/09/21/revrb-lantern.html","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-predictable-session-token-with-validation-bypass","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00627,"epssPercentile":0.4783,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-22T17:22:31.916185Z"},"ingestedAt":"2026-09-22T16:06:00.493Z","slug":"CVE-2026-80154","body":"## Overview\n\nAll firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":52.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}