OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-80147

CRITICAL · CVSS 9.9 EPSS 0.46% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability affects Lantronix SLC8000, EMG8500/EMG7500, and SLB882/SLCx-03/SLCx-02 devices running specific firmware versions, allowing authenticated attackers to exploit a stack-based buffer overflow via an undocumented command. This can lead to arbitrary code execution, resulting in a complete compromise of the device's confidentiality, integrity, and availability, which may also impact connected serial devices. Organizations using these products should prioritize immediate remediation to mitigate the critical risk associated with this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-80147
Severity
CRITICAL
CVSS
9.9
EPSS
0.46%

Original NVD Description

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by exploiting an undocumented mfc eeprom write command that copies unbounded user input into a bounded stack buffer before passing it to a system() call. Attackers can authenticate as any user to the terminal or CLI interface and supply an oversized input to trigger the overflow, potentially achieving complete loss of confidentiality, integrity, and availability on the affected device and impacting downstream serial-attached devices.