Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability t…
Critical CVSS 9.9
Summary
Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom read command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate as any user to the terminal or CLI interface an…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://revrb.net/2026/09/21/revrb-lantern.html
- https://ts.lantronix.com/ftp/SLC9000/9.7.0.2R1/
- https://ts.lantronix.com/ftp/emg/EMG_7500/9.7.0.1R2/
- https://ts.lantronix.com/ftp/emg/EMG_8500/9.7.0.1R2/
- https://ts.lantronix.com/ftp/slc8000/9.7.0.2R1/
- https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-stack-based-buffer-overflow-via-mfc-eeprom-read
Timeline
- nvd_ingest NVD