VYPR
Vendor

Lantronix

Products
31
CVEs
58
Across products
154
Status
Private

Products

31
View all 31 products →

Recent CVEs

58
View all 58 CVEs →
  • CVE-2025-67038CriKEVMar 11, 2026
    risk 0.77cvss 9.8epss 0.19

    An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allow attackers to inject arbitrary OS…

  • CVE-2021-21892CriDec 22, 2021
    risk 0.67cvss 9.9epss 0.30

    A stack-based buffer overflow vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21881CriDec 22, 2021
    risk 0.67cvss 9.9epss 0.36

    An OS command injection vulnerability exists in the Web Manager Wireless Network Scanner functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2026-80155CriSep 22, 2026
    risk 0.65cvss 10.0epss 0.02

    Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web management portal upload endpoint that allows…

  • CVE-2026-80144CriSep 22, 2026
    risk 0.65cvss 9.9epss 0.03

    Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by…

  • CVE-2026-80143CriSep 22, 2026
    risk 0.65cvss 9.9epss 0.03

    Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by…

  • CVE-2021-21889CriDec 22, 2021
    risk 0.65cvss 9.9epss 0.03

    A stack-based buffer overflow vulnerability exists in the Web Manager Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21883CriDec 22, 2021
    risk 0.65cvss 9.9epss 0.06

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Ping functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2021-21872CriDec 22, 2021
    risk 0.65cvss 9.9epss 0.06

    An OS command injection vulnerability exists in the Web Manager Diagnostics: Traceroute functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger…

  • CVE-2026-80147CriSep 22, 2026
    risk 0.64cvss 9.9epss 0.01

    Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by…

  • CVE-2026-80146CriSep 22, 2026
    risk 0.64cvss 9.9epss 0.01

    Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to potentially execute arbitrary code by…

  • CVE-2025-67039CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appending a specific suffix to the URL and by sending an Authorization header that uses "admin" as the username.

  • CVE-2018-12925CriJun 28, 2018
    risk 0.64cvss 9.8epss 0.01

    Baseon Lantronix MSS devices do not require a password for TELNET access.

  • CVE-2016-4325CriMay 14, 2016
    risk 0.64cvss 9.8epss 0.02

    Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.

  • CVE-2026-80154CriSep 22, 2026
    risk 0.62cvss 9.6epss 0.01

    All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session tokens of logged-in users and bypass…

  • CVE-2021-21884CriDec 22, 2021
    risk 0.60cvss 9.1epss 0.05

    An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this…

  • CVE-2026-80156CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management portal upload endpoint that allows…

  • CVE-2026-80152CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.03

    Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission…

  • CVE-2026-80151CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.03

    Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission…

  • CVE-2026-80145CriSep 22, 2026
    risk 0.59cvss 9.1epss 0.03

    Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell…