Sceawere
Vulnerability Detail
CVE-2026-80150UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Lantronix SSRF via WebSSH/WebTelnet
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- LANTRONIX
- Product
- SLC8000
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet listener that allows unauthenticated attackers to cause the affected device to establish Telnet connections to attacker-controlled endpoints. The custom shellinaboxd uses the rooturl parameter from the web connection to determine its own IP address; by modifying this parameter an attacker redirects the Telnet terminal connection to an arbitrary host or IP. Attackers can use this capability to enumerate or communicate with internal network endpoints that would otherwise be inaccessible.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-22T16:18:01.313Z",
"pubdate": "2026-09-22T16:18:01.313Z",
"executiveSummary": "A server-side request forgery (SSRF) vulnerability exists within the WebSSH/WebTelnet listener components of multiple Lantronix console server products. This flaw originates from improper input validation of the 'rooturl' parameter utilized by the custom 'shellinaboxd' service. Successful exploitation allows unauthenticated remote attackers to force the affected device to initiate outbound Telnet connections to arbitrary IP addresses or hosts. By leveraging the device as a proxy, adversaries can bypass network segmentation to perform internal reconnaissance, enumerate private network services, and interact with internal endpoints that are otherwise unreachable from the public internet. The vulnerability poses a significant risk to organizational internal security posture by effectively turning network-critical infrastructure into a conduit for lateral movement. Impacted products include Lantronix SLC8000, EMG8500, EMG7500, and SLB882. Exploitation does not require prior authentication, making it a highly accessible vector for unauthorized network access.",
"technicalDetails": "The vulnerability is rooted in the implementation of the 'shellinaboxd' service, which dynamically determines its own network address configuration based on the 'rooturl' parameter provided during the initiation of a web-based terminal session. Because the application fails to perform rigorous input validation or sanitization on this parameter, it remains susceptible to manipulation by an unauthenticated remote user.\nThe attack flow commences when an adversary sends a specially crafted HTTP request to the WebSSH/WebTelnet interface. By injecting a malicious value into the 'rooturl' parameter, the attacker forces the 'shellinaboxd' service to misinterpret its connection target. Specifically, the service utilizes this parameter to establish the Telnet terminal bridge; by supplying an arbitrary IP address or hostname in the parameter, the attacker redirects the underlying Telnet session to the specified remote host.\nThe vulnerable component, 'shellinaboxd', acts as the intermediary. When the parameter is manipulated, the device initiates an outbound connection, effectively performing an SSRF. Because the device is situated within the target's internal infrastructure, it acts as a pivot point. The service, operating with administrative context, initiates these requests without requiring the attacker to have pre-existing credentials or privilege levels on the target device.\nNetwork exposure is significant, as the WebSSH/WebTelnet listener typically resides on the management interface of the appliance. Post-exploitation, an attacker can conduct internal port scanning, service banner grabbing, and interact with internal-only APIs or web management interfaces that lack external exposure. This vulnerability effectively facilitates the traversal of network perimeter defenses, allowing an attacker to map internal topologies and exploit secondary services within the local area network. Since 'shellinaboxd' initiates the connection, the traffic originates from a trusted infrastructure component, which may allow it to bypass traditional firewall rules that restrict ingress traffic but permit egress traffic from management appliances."
}