important · Firmware
Unauthenticated requests can turn Lantronix out-of-band controllers into code-execution footholds.
Affects
Lantronix SLC 9000, SLC 8000, EMG 8500 and EMG 7500 autonomous out-of-band console-management appliances for serial-connected infrastructure.
Authentication bypass or predictable session tokens reach arbitrary-write functionality that the vendor says leads to code execution. The portal's default bind interface, the execution UID and the exact capability against attached serial devices remain unknown. The published fixes were not reviewed for this brief, so this cannot lead.
Detail and 3 sources
Chain to watch
Reach the web management portal without credentials→↓Bypass authentication or derive a valid session token→↓Write attacker-controlled data to security-relevant filesystem locations→↓Obtain code execution on the controller→↓The execution UID and exact capability against downstream serial-connected devices are not published.
Unverified chainRun a benign identity command through the affected upload path on stock firmware, record the payload UID, and separately demonstrate a harmless command against an attached lab serial target.