Database/Firmware, BMC & network fabric

Lantronix console servers: command injection in the NFS download CLI yields root on the out-of-band management device
Impact
The CLI's 'set nfs download' command passes unsanitized input to system(), so an authenticated user holding the services permission gets arbitrary shell commands as root on the console server. These devices sit on the management network and hold serial console access to the servers, switches and PDUs behind them, so root on the console server means a foothold on the out-of-band path itself and the ability to reach downstream serial-attached equipment - including BIOS and BMC consoles that assume physical-equivalent trust. The CVSS 4.0 vector rates subsequent-system confidentiality, integrity and availability all high, reflecting that downstream reach. SLB882, SLCx-03 and SLCx-02 have no fixed firmware at all.
Who can reach it
An attacker who can reach the device's terminal or CLI interface - in practice anyone on the management VLAN - and who authenticates with an account holding the services permission. Authentication is required.
What to do
Flash firmware: SLC8000 to v9.7.0.3, SLC9000 to v9.7.0.2, EMG8500/EMG7500 to v9.7.0.1, images on the Lantronix FTP site. A console-server flash takes the out-of-band path for its attached racks out of service during the reboot, so schedule it when you do not need serial access. SLB882, SLCx-03 and SLCx-02 have no fix in any firmware version - for those, mitigate only: keep the management interface off any routable network, and stop granting the services permission to accounts that do not need it.
References
Related entries
- Arista EOS (redundant supervisor, RPR/SSO): On modular chassis with dual supervisors running RPR or SSO redundancyCVE-2023-24509 · Arista EOS (redundant supervisor, RPR/SSO)Critical
- Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2): The controller verifiesCVE-2025-53696 · Software House iSTAR Ultra firmware verification and web application (tested through 6.9.2)Critical
- Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestationCVE-2026-22696 · Phala dcap-qvl - the Rust/npm/Python DCAP quote verification library used to verify Intel SGX and TDX attestation…Critical
- Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management cardCVE-2026-44402 · Voltronic Power SNMP Web Pro 1.1 (upload.cgi firmware update endpoint)Critical
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.