---
id: CVE-2026-80154
title: >-
  All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882,
  SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web
  management portal that allows unauthenticated attackers to derive valid
  session…
summary: >-
  All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882,
  SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web
  management portal that allows unauthenticated attackers to derive valid
  session…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-330
vendor: LANTRONIX
product: SLC8000
affected:
  - SLC8000
  - EMG8500
  - EMG7500
  - SLB882
  - SLCx-03
  - SLCx-02
published: '2026-09-22'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:17:31.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80154'
references:
  - url: 'https://revrb.net/2026/09/21/revrb-lantern.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-predictable-session-token-with-validation-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00627
epssPercentile: 0.4783
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T17:22:31.916185Z'
ingestedAt: '2026-09-22T16:06:00.493Z'
---

## Overview

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
