GPU VulnDB

Database/Firmware, BMC & network fabric

Lantronix console servers: command injection in the NFS download CLI yields root on the out-of-band management device

CVSS 9.4CVE-2026-80151Firmware, BMC & network fabriccurated

Impact

The CLI's 'set nfs download' command passes unsanitized input to system(), so an authenticated user holding the services permission gets arbitrary shell commands as root on the console server. These devices sit on the management network and hold serial console access to the servers, switches and PDUs behind them, so root on the console server means a foothold on the out-of-band path itself and the ability to reach downstream serial-attached equipment - including BIOS and BMC consoles that assume physical-equivalent trust. The CVSS 4.0 vector rates subsequent-system confidentiality, integrity and availability all high, reflecting that downstream reach. SLB882, SLCx-03 and SLCx-02 have no fixed firmware at all.

Who can reach it

An attacker who can reach the device's terminal or CLI interface - in practice anyone on the management VLAN - and who authenticates with an account holding the services permission. Authentication is required.

What to do

Flash firmware: SLC8000 to v9.7.0.3, SLC9000 to v9.7.0.2, EMG8500/EMG7500 to v9.7.0.1, images on the Lantronix FTP site. A console-server flash takes the out-of-band path for its attached racks out of service during the reboot, so schedule it when you do not need serial access. SLB882, SLCx-03 and SLCx-02 have no fix in any firmware version - for those, mitigate only: keep the management interface off any routable network, and stop granting the services permission to accounts that do not need it.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.