Sceawere
Vulnerability Detail
CVE-2026-80154UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Lantronix Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 3h ago
- Vendor
- LANTRONIX
- Product
- SLC8000
- Attack Type
- Use of Insufficiently Random Values
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
All firmware versions of Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-22T16:18:01.767Z",
"pubdate": "2026-09-22T16:18:01.767Z",
"executiveSummary": "A critical authentication bypass vulnerability exists within the web management portals of various Lantronix console managers and device servers, including SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 series.\nThe vulnerability stems from deterministic session token generation and flawed URI path routing, allowing unauthenticated attackers to hijack active user sessions.\nBy deriving valid session tokens based on device model and system time, an attacker can bypass security controls such as source IP address and User-Agent validation.\nThis flaw allows remote attackers to gain elevated privileges without valid credentials, posing a significant risk to the integrity and confidentiality of the management interface.\nSuccessful exploitation facilitates unauthorized administrative access to the affected device, potentially leading to full system compromise and the ability to interact with downstream serial-attached hardware.\nThe vulnerability requires no prior authentication and can be exploited over the network by identifying a target device and timing session token generation.",
"technicalDetails": "The core of the vulnerability lies in the deterministic nature of session token generation within the device's web management interface. Tokens are generated based on the device model and the system time at a one-second resolution.\nBecause the search space for these tokens is limited, an attacker can enumerate the possible active tokens at any given time without needing legitimate credentials.\nThe web server utilizes flawed file extension handling within its path routing mechanism. By constructing a specially crafted URI, an attacker can cause the application to process requests in a way that bypasses intended per-session source-address and User-Agent validation checks.\nThe exploitation flow proceeds as follows: First, the attacker identifies the target device model. Second, the attacker synchronizes their observation of the target's system time to narrow down the possible token pool for the desired timeframe.\nThird, the attacker generates a list of candidate session tokens derived from the deterministic algorithm. Fourth, the attacker crafts a malicious URI that leverages the server's path-routing behavior to bypass the IP validation logic.\nFinally, the attacker submits the crafted request using a derived token. If the token corresponds to an active session, the web server grants the attacker the authenticated state of that user, providing elevated privileges.\nAffected products include all firmware versions of the Lantronix SLC8000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02.\nThe post-exploitation impact is severe, as the attacker obtains full administrative access to the management portal. This level of access permits the configuration of the device and provides control over any serial-attached devices managed by the unit, potentially extending the attacker's reach into sensitive operational technology (OT) infrastructure."
}