← All Advisories

Lantronix SLC8000, SLC9000, EMG, and SLB Series Web Portal Derives Session Tokens Deterministically from Device Model and Current Second, Letting Unauthenticated Attackers Predict and Forge Valid Sessions on All Firmware Versions

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-80154

Key Details

CVECVE-2026-80154
CVSS Score / Version9.6 (Critical) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high.
Classified asCWE-330 (Use of Insufficiently Random Values)

What to Know

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass source IP and User-Agent validation. Session tokens are generated deterministically from the device model and the current time at one-second resolution, resulting in a small enumerable set of possible active tokens. Attackers can construct a crafted URI that exploits file extension handling in the web server path routing to bypass per-session source-address validation, then use a derived token from a different source address to gain elevated privileges on the affected device and potentially impact downstream serial-attached devices. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-80154
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-80154