{"id":"CVE-2026-80154","published":"2026-09-22T16:18:01.767","lastModified":"2026-09-24T20:17:31.517","description":"All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwes":["CWE-330"],"vendors":[],"products":[],"references":[{"url":"https://revrb.net/2026/09/21/revrb-lantern.html","tags":[]},{"url":"https://www.vulncheck.com/advisories/lantronix-autonomous-out-of-band-devices-predictable-session-token-with-validation-bypass","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated attackers to derive valid session tokens and bypass security checks, leading to unauthorized access and potential device control.","exploitability":"Exploitation is moderately hard due to the need to construct a specific URI, but preconditions include access to the web management portal.","blast_radius":"If exploited, attackers could gain full control over the device and its connected serial-attached devices, leading to significant operational disruptions.","remediation":"Disable the web management portal feature or restrict access to it from untrusted networks.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","session","device-control"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:53:37.210Z"}}