<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://revrb.net/feed.xml" rel="self" type="application/atom+xml" /><link href="https://revrb.net/" rel="alternate" type="text/html" /><updated>2026-09-21T18:28:07+00:00</updated><id>https://revrb.net/feed.xml</id><title type="html">RE/VRb LLC</title><subtitle>Independent security research organization</subtitle><entry><title type="html">REVRB-LANTERN: Security Research on Lantronix Autonomous Out-of-Band Devices</title><link href="https://revrb.net/2026/09/21/revrb-lantern.html" rel="alternate" type="text/html" title="REVRB-LANTERN: Security Research on Lantronix Autonomous Out-of-Band Devices" /><published>2026-09-21T13:28:19+00:00</published><updated>2026-09-21T13:28:19+00:00</updated><id>https://revrb.net/2026/09/21/revrb-lantern</id><content type="html" xml:base="https://revrb.net/2026/09/21/revrb-lantern.html"><![CDATA[<p>RE/VRb LLC conducts independent research to improve cyber infrastructure security. The following report details research conducted without contract or bounty, representing over four months of discovery and coordination by a single researcher. You can support our ongoing efforts <a href="https://ko-fi.com/revrb">here</a>.</p>

<p><strong>Table of Contents:</strong></p>

<ul id="markdown-toc">
  <li><a href="#summary" id="markdown-toc-summary">Summary</a></li>
  <li><a href="#device-market" id="markdown-toc-device-market">Device Market</a></li>
  <li><a href="#findings" id="markdown-toc-findings">Findings</a>    <ul>
      <li><a href="#technical-details" id="markdown-toc-technical-details">Technical Details</a>        <ul>
          <li><a href="#web-management-portal" id="markdown-toc-web-management-portal">Web Management Portal</a></li>
          <li><a href="#webshell" id="markdown-toc-webshell">WebShell</a></li>
          <li><a href="#cli" id="markdown-toc-cli">CLI</a></li>
        </ul>
      </li>
    </ul>
  </li>
  <li><a href="#footnote-concerning-the-slc9000" id="markdown-toc-footnote-concerning-the-slc9000">Footnote Concerning the SLC9000</a></li>
  <li><a href="#gnu-general-public-license-gpl-code" id="markdown-toc-gnu-general-public-license-gpl-code">GNU General Public License (GPL) Code</a></li>
  <li><a href="#future-work" id="markdown-toc-future-work">Future Work</a></li>
</ul>

<h2 id="summary">Summary</h2>

<p>RE/VRb discovered and coordinated fourteen vulnerabilities in Lantronix Autonomous Out-of-Band Devices, including chains that can lead to unauthenticated remote code execution. These devices appear to be prevalent in data centers, telecom networks, and in state and local services, among other markets. By design, these devices may introduce a secondary path into a user network for managing network or other serial-managed devices in case of a primary network failure. In typical deployments, these devices sit alongside management-layer infrastructure and may hold credentials and/or provide control over devices and physical systems that communicate over serial.</p>

<p>Per Lantronix, the reported CVEs are addressed in recent patches (v9.7.0.5 for the SLC8000 and v9.7.0.1 for the EMG series), but per our research into v9.7.0.5 for the SLC8000, REVRB-LANTERN-13 (CVE-2026-80154) remains unremediated.</p>

<p>The following devices were confirmed to be vulnerable to one or more of the findings detailed below:</p>

<ul>
  <li>Lantronix SLC8000</li>
  <li>Lantronix EMG8500</li>
  <li>Lantronix EMG7500</li>
  <li>Lantronix SLB882</li>
  <li>Lantronix SLCx-03</li>
  <li>Lantronix SLCx-02</li>
</ul>

<p>Additionally, we asked Lantronix about the applicability of our findings to the newly released SLC9000, which we assessed may share portions of the same codebase as the devices listed above. Despite multiple requests, Lantronix did not confirm or deny our findings against the SLC9000, and asked that we “refrain from mentioning it in [our] publication.” Our findings concerning the SLC9000 can be found below. If you own an SLC9000 and would like to coordinate further research, please reach out to research@revrb.net.</p>

<p>We recommend SLC9000 owners review the 18 September 2026 firmware update, which Lantronix published citing security vulnerabilities, reach out to Lantronix support with any questions about said vulnerabilities, and apply where appropriate.</p>

<p>SLC8000 owners and owners of EMG-series devices are recommended to patch their devices as soon as possible to obtain available remediations and to adopt/continue defense-in-depth and strong network monitoring practices to respond to yet-unknown vulnerabilities.</p>

<p>Owners of SLB-series devices are recommended to disconnect or layer defenses over their SLBs and to reach out to Lantronix concerning patch availability; Lantronix’s product discontinuation notice indicates warranty and software support through 31 December 2028<sup id="fnref:slb-eol" role="doc-noteref"><a href="#fn:slb-eol" class="footnote" rel="footnote">1</a></sup>, but no patch appears to have been made available.</p>

<p>Owners of SLCx-02 and SLCx-03 devices are recommended to decommission these devices, as they are end-of-support and no patch is expected to be made available.</p>

<h2 id="device-market">Device Market</h2>

<p>The following market and deployment information is aggregated from publicly available sources external to RE/VRb. RE/VRb makes no claim that any named or unnamed organization is currently a Lantronix customer, currently operates a product affected by the vulnerabilities described in this report, or is inherently or immediately vulnerable due to this disclosure. Where a source attributes a deployment to a named organization, the attribution is the source’s; RE/VRb has not independently verified any deployment described here. This information is provided solely to demonstrate the scale and reach of the mentioned devices and the importance of this research.</p>

<p><strong>AI and High-Performance Computing:</strong> SambaNova documentation explicitly identifies the SLC8000 as the serial console server in its SambaRack SN40L-16 infrastructure,<sup id="fnref:sambanova-slc8000" role="doc-noteref"><a href="#fn:sambanova-slc8000" class="footnote" rel="footnote">2</a></sup> while a recent Lantronix earnings call states that Lantronix won a SambaNova design for the newer SLC9000.<sup id="fnref:sambanova-slc9000" role="doc-noteref"><a href="#fn:sambanova-slc9000" class="footnote" rel="footnote">3</a></sup> SambaNova has separately documented DataScale, SambaNova Suite, or SN40L infrastructure deployments at multiple US Department of Energy National Laboratories,<sup id="fnref:usdoe-argonne" role="doc-noteref"><a href="#fn:usdoe-argonne" class="footnote" rel="footnote">4</a></sup><sup id="fnref:usdoe-oakridge" role="doc-noteref"><a href="#fn:usdoe-oakridge" class="footnote" rel="footnote">5</a></sup><sup id="fnref:usdoe-losalamos" role="doc-noteref"><a href="#fn:usdoe-losalamos" class="footnote" rel="footnote">6</a></sup><sup id="fnref:usdoe-lawrencelivermore" role="doc-noteref"><a href="#fn:usdoe-lawrencelivermore" class="footnote" rel="footnote">7</a></sup> US and international high-performance computing (HPC) centers,<sup id="fnref:hpc-tacc" role="doc-noteref"><a href="#fn:hpc-tacc" class="footnote" rel="footnote">8</a></sup><sup id="fnref:hpc-riken" role="doc-noteref"><a href="#fn:hpc-riken" class="footnote" rel="footnote">9</a></sup> and to power international sovereign AI providers.<sup id="fnref:sambanova-sovai" role="doc-noteref"><a href="#fn:sambanova-sovai" class="footnote" rel="footnote">10</a></sup></p>

<p><strong>Government and Public Safety Infrastructure:</strong> The communications-equipment inventory published with the US Defense Information Systems Agency’s (DISA) Capacity Services Communications III (CSC III) indefinite-delivery/indefinite-quantity solicitation lists multiple SLC8000 models alongside other enterprise equipment.<sup id="fnref:disa-csciii" role="doc-noteref"><a href="#fn:disa-csciii" class="footnote" rel="footnote">11</a></sup> CSC III is intended to provide scalable communications infrastructure services throughout DISA and other approved locations across the DoD worldwide. During a 2019 earnings call, while discussing the SLC8000, Lantronix reported strong demand for its out-of-band management devices from customers including the Swedish Defence Administration.<sup id="fnref:ltrx-2019-q2" role="doc-noteref"><a href="#fn:ltrx-2019-q2" class="footnote" rel="footnote">12</a></sup> The SLC8000 also appears as a component of Motorola Solutions ASTRO 25 public-safety radio infrastructure.<sup id="fnref:moto-contract" role="doc-noteref"><a href="#fn:moto-contract" class="footnote" rel="footnote">13</a></sup> We were able to identify multiple US state and city radio acquisition contracts that itemized the SLC8000 or its expansion modules.</p>

<p><strong>Telecommunications, Data Centers, and Enterprise IT:</strong> A 2018 use-case describes an unnamed “telecom giant” deploying SLC8000s across geographically distributed data centers.<sup id="fnref:telecom-giant" role="doc-noteref"><a href="#fn:telecom-giant" class="footnote" rel="footnote">14</a></sup> Similarly, a 2016 use-case describes an unnamed “leading nationwide provider of cable television” deploying SLC8000s across hundreds of data centers or points-of-presence.<sup id="fnref:cable-giant" role="doc-noteref"><a href="#fn:cable-giant" class="footnote" rel="footnote">15</a></sup> A 2016 Lantronix SLC8000 battle card states that the SLC8000 is “Used by Avaya, Cisco, Brocade, NetApp, T-Mobile and others in their development labs and data centers.”<sup id="fnref:battle-card" role="doc-noteref"><a href="#fn:battle-card" class="footnote" rel="footnote">16</a></sup> Similarly, on a slide discussing share gain for the SLC8000, a 2017 Lantronix investor presentation lists NetApp, F5, Hewlett Packard Enterprise, Avaya, Brocade, Samsung, T-Mobile, Symantec, Yahoo!, PwC, and Vodafone as “Select Customers”<sup id="fnref:select-customers" role="doc-noteref"><a href="#fn:select-customers" class="footnote" rel="footnote">17</a></sup></p>

<p><strong>EMG and SLB Deployments:</strong> A 2023 Lantronix case study indicates that the EMG8500 is used by the University of Cambridge.<sup id="fnref:u-cambridge" role="doc-noteref"><a href="#fn:u-cambridge" class="footnote" rel="footnote">18</a></sup> Lantronix earnings calls explicitly describe a large Verizon SLB rollout and continued purchases<sup id="fnref:ltrx-2016-q1" role="doc-noteref"><a href="#fn:ltrx-2016-q1" class="footnote" rel="footnote">19</a></sup>, and separately describe an SLB rollout through a solution provider that had won a contract with the Four Seasons Hotel Group.<sup id="fnref:ltrx-2019-q2:1" role="doc-noteref"><a href="#fn:ltrx-2019-q2" class="footnote" rel="footnote">12</a></sup> Finally, a 2014 Lantronix publication states that an SLB was deployed at the Aloha Cabled Observatory, approximately three miles below the sea surface.<sup id="fnref:aloha-observatory" role="doc-noteref"><a href="#fn:aloha-observatory" class="footnote" rel="footnote">20</a></sup></p>

<h2 id="findings">Findings</h2>

<p><strong>Descriptions:</strong></p>

<table>
  <thead>
    <tr>
      <th>Internal Marking</th>
      <th>Associated CVE</th>
      <th>CVE Description</th>
      <th>Recommended CVSS3.1</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>REVRB-LANTERN-01</td>
      <td>CVE-2026-80143</td>
      <td>An attacker that can authenticate as any user to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.9/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-02</td>
      <td>CVE-2026-80144</td>
      <td>An attacker that can authenticate as any user to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.9/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-03</td>
      <td>CVE-2026-80145</td>
      <td>An attacker that can authenticate as any user with the ‘services’ permission to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.1/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-04</td>
      <td>CVE-2026-80146</td>
      <td>An attacker that can authenticate as any user to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can cause a stack-based buffer overflow which may lead to code execution. This can cause a complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.9/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-05</td>
      <td>CVE-2026-80147</td>
      <td>An attacker that can authenticate as any user to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can cause a stack-based buffer overflow which may lead to code execution. This can cause a complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.9/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-06</td>
      <td>CVE-2026-80148</td>
      <td>An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force a server-side request forgery that causes the affected device to create SSH connections to attacker-defined endpoints. An attacker could use this capability to enumerate and/or communicate with endpoints they otherwise would not have access to.</td>
      <td>8.6/High</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-07</td>
      <td>CVE-2026-80149</td>
      <td>An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force a server-side request forgery that causes the affected device to create SSH connections to attacker-defined endpoints. An attacker could use this capability to enumerate and/or communicate with endpoints they otherwise would not have access to.</td>
      <td>8.6/High</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-08</td>
      <td>CVE-2026-80150</td>
      <td>An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force a server-side request forgery that causes the affected device to create telnet connections to attacker-defined endpoints. An attacker could use this capability to enumerate and/or communicate with endpoints they otherwise would not have access to.</td>
      <td>8.6/High</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-09</td>
      <td>CVE-2018-16789</td>
      <td>An unauthenticated attacker that can access the WebSSH/WebTelnet listener on Lantronix Autonomous Out-of-Band devices can force the listener into an infinite loop using CVE-2018-16789, denying service to the endpoint.</td>
      <td>7.5/High</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-10</td>
      <td>CVE-2026-80151</td>
      <td>An attacker that can authenticate as any user with the ‘services’ permission to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.1/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-11</td>
      <td>CVE-2026-80152</td>
      <td>An attacker that can authenticate as any user with the ‘services’ permission to the terminal/CLI of Lantronix Autonomous Out-of-Band devices can execute shell commands as root. This can cause complete loss of confidentiality, integrity, and availability for the affected device with the potential to impact downstream serial-attached devices.</td>
      <td>9.1/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-12</td>
      <td>N/A</td>
      <td>This represents an internal finding that was later discovered to be a false positive</td>
      <td>N/A</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-13</td>
      <td>CVE-2026-80154</td>
      <td>An unauthenticated attacker that can access the web management portal on Lantronix Autonomous Out-of-Band devices can derive session tokens of logged-in users and bypass validation of those tokens in order to elevate privileges.</td>
      <td>9.6/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-14</td>
      <td>CVE-2026-80155</td>
      <td>An unauthenticated attacker that can access the web management portal on Lantronix Autonomous Out-of-Band devices can bypass authentication checks to pull key configuration files (such as usernames and hashed passwords) and upload files to key filesystem locations, leading to remote code execution and the ability to impact downstream serial-connected devices.</td>
      <td>10.0/Critical</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-15</td>
      <td>CVE-2026-80156</td>
      <td>An attacker that can authenticate to the upload endpoint of the web management portal of Lantronix Autonomous Out-of-Band devices can write arbitrary data to any location on that device’s disk, leading to remote code execution and the ability to impact downstream serial-connected devices.</td>
      <td>9.1/Critical</td>
    </tr>
  </tbody>
</table>

<p><strong>By Device/Firmware Applicability:</strong></p>

<table>
  <thead>
    <tr>
      <th>Internal Marking</th>
      <th>Associated CVE</th>
      <th>SLC8000</th>
      <th>EMG8500/EMG7500</th>
      <th>SLB882</th>
      <th>SLCx-03</th>
      <th>SLCx-02</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>REVRB-LANTERN-01</td>
      <td>CVE-2026-80143</td>
      <td>&lt;v9.7.0.2</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-02</td>
      <td>CVE-2026-80144</td>
      <td>&lt;v9.7.0.2</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-03</td>
      <td>CVE-2026-80145</td>
      <td>&lt;v9.7.0.2</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-04</td>
      <td>CVE-2026-80146</td>
      <td>&lt;v9.7.0.2</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-05</td>
      <td>CVE-2026-80147</td>
      <td>&lt;v9.7.0.2</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-06</td>
      <td>CVE-2026-80148</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>N/A</td>
      <td>N/A</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-07</td>
      <td>CVE-2026-80149</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>N/A</td>
      <td>N/A</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-08</td>
      <td>CVE-2026-80150</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>N/A</td>
      <td>N/A</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-09</td>
      <td>CVE-2018-16789</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>N/A</td>
      <td>N/A</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-10</td>
      <td>CVE-2026-80151</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-11</td>
      <td>CVE-2026-80152</td>
      <td>&lt;v9.7.0.3</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-13</td>
      <td>CVE-2026-80154</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-14</td>
      <td>CVE-2026-80155</td>
      <td>&lt;v9.7.0.5</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
    <tr>
      <td>REVRB-LANTERN-15</td>
      <td>CVE-2026-80156</td>
      <td>&lt;v9.7.0.5</td>
      <td>&lt;v9.7.0.1</td>
      <td>All versions</td>
      <td>All versions</td>
      <td>All versions</td>
    </tr>
  </tbody>
</table>

<h3 id="technical-details">Technical Details</h3>

<h4 id="web-management-portal">Web Management Portal</h4>

<p><strong>REVRB-LANTERN-13:</strong> Lantronix Autonomous Out-of-Band devices create their session token from the device model and the current time at a resolution of one second and automatically expire them after 15 minutes. For the span of time a session token could possibly be valid, there are only 900 possible session tokens, with some minor variation based on how often the cookie expiration script runs. An attacker can retrieve a current unauthenticated session token from <code class="language-plaintext highlighter-rouge">login.htm</code>, deriving the device model and time to generate all 900 possible active tokens.</p>

<p>An attacker must then overcome the source IP and User-Agent validation stored in <code class="language-plaintext highlighter-rouge">/tmp/.save/cookies/sessions.txt</code>. In certain areas of the web server’s path handling, file extension checks are performed that allow for bypassing this check. An attacker can create a crafted URI that abuses these checks to allow the use of a stolen session token.</p>

<p><strong>REVRB-LANTERN-14:</strong> The web configuration server, when validating the session token for upload endpoint, performs the following steps:</p>

<ul>
  <li>Splits the cookie by ‘=’ and parses the time from the second half, only checking that it’s newer than the boot time of the device.</li>
  <li>Checks that the cookie exists as a file in <code class="language-plaintext highlighter-rouge">/tmp/.save/cookies/</code>; i.e.: <code class="language-plaintext highlighter-rouge">/tmp/.save/cookies/session=S0F00280d48546-38845</code></li>
  <li>Checks that the contents of that file don’t begin with “COOKIE_USER”</li>
  <li>Loads the username and permissions from the cookie file</li>
</ul>

<p>An attacker can bypass the first check simply by creating a cookie with the correct timestamp - as mentioned before, the cookies are derived from the device model and a timestamp.</p>

<p>For check number 2, an attacker can abuse a <code class="language-plaintext highlighter-rouge">snprintf</code> call used to build the filepath to check - <code class="language-plaintext highlighter-rouge">snprintf(filename, 129, "%s/%s", "/tmp/.save/cookies", cookie)</code>. By providing a cookie of a specific length, said attacker can cause the filepath to truncate on the required <code class="language-plaintext highlighter-rouge">=</code> and leverage path traversal to identify an arbitrary file on disk for checks 3 and 4.</p>

<p>An attacker can use these to point the server to <code class="language-plaintext highlighter-rouge">/etc/.lusers</code> - a file on-device that stores the local users and starts with <code class="language-plaintext highlighter-rouge">sysadmin</code> - in order to bypass checks 3 and 4.</p>

<p>The final cookie ends up looking something <em>like</em> <code class="language-plaintext highlighter-rouge">Cookie: ../../..///////////////////////////////////////////////////////////////////////////////////////////etc/.lusers=S0F00280d48546-38845</code> - everything past the ‘=’ passing cookie format and timestamp checks, and everything prior becoming truncated to <code class="language-plaintext highlighter-rouge">../../..///////////////////////////////////////////////////////////////////////////////////////////etc/.lusers</code> as the file to use to check the validity of the cookie.</p>

<p>This allows an attacker to upload to and/or pull from critical file locations, such as key stores.</p>

<p><strong>REVRB-LANTERN-15:</strong> When validating the upload filename to avoid pathing characters, the web management portal first checks for <code class="language-plaintext highlighter-rouge">\</code> and strips them. If <code class="language-plaintext highlighter-rouge">\</code> is discovered, however, then checks for <code class="language-plaintext highlighter-rouge">/</code> never occur, allowing an attacker to upload a filename like <code class="language-plaintext highlighter-rouge">pre\../../../bin/busybox</code>, allowing arbitrary data to be uploaded anywhere on disk instead of the intended controlled locations.</p>

<h4 id="webshell">WebShell</h4>

<p>Lantronix Autonomous Out-of-Band devices use a custom <code class="language-plaintext highlighter-rouge">shellinaboxd</code> to provide terminal access across the web browser. SLCx-02 and SLCx-03 devices do not have this feature, and are therefore not vulnerable to the following.</p>

<p><strong>REVRB-LANTERN-09:</strong> The custom <code class="language-plaintext highlighter-rouge">shellinaboxd</code> in-use is vulnerable to CVE-2018-16789, which allows an attacker to send a malformed multipart-form request that sends the service into an infinite loop.</p>

<p><strong>REVRB-LANTERN-06:</strong> The custom shellinaboxd builds its connection target using user input for the username passed to a <code class="language-plaintext highlighter-rouge">snprintf</code> call: <code class="language-plaintext highlighter-rouge">snprintf((char *)&amp;host,0x200,"%s@%s",input_buf,this_device_ip)</code>.  Because the <code class="language-plaintext highlighter-rouge">@&lt;device_ip&gt;</code> comes <em>after</em> user input, and because user input is unbounded, an attacker can pass in an overly-long connection string and truncate the device IP entirely. By padding an IP with 0s, an attacker can point this connection string to any IP (though they will have to perform octal conversions first, since 0-prefixed numbers are interpreted as octal on the SLC and EMG devices.) i.e.: <code class="language-plaintext highlighter-rouge">root@000...00012.0.0.1</code> allows an attacker to point the resulting SSH connection to <code class="language-plaintext highlighter-rouge">root@10.0.0.1</code>.</p>

<p><strong>REVRB-LANTERN-07, 08:</strong> When building the terminal connection for the user, the custom <code class="language-plaintext highlighter-rouge">shellinaboxd</code> uses the <code class="language-plaintext highlighter-rouge">rooturl</code> parameter provided by the web connection to determine its own IP address. An attacker can modify this parameter to cause the terminal connection to be made to an arbitrary host or IP.  This is reported as two separate findings, one for the SSH section of the codebase and one for the Telnet portion.</p>

<h4 id="cli">CLI</h4>

<p><strong>REVRB-LANTERN-01, 02, 04, 05:</strong> An undocumented set of commands exists in the <code class="language-plaintext highlighter-rouge">cli</code> management binary. Among them are <code class="language-plaintext highlighter-rouge">mfc eeprom read</code> and <code class="language-plaintext highlighter-rouge">mfc eeprom write</code>, which both pass unbounded/unsanitized user input into a bounded stack buffer, and then to a call to <code class="language-plaintext highlighter-rouge">system</code>.</p>

<p><strong>REVRB-LANTERN-03:</strong> <code class="language-plaintext highlighter-rouge">set cifs password</code> passes unsanitized user input into a call to <code class="language-plaintext highlighter-rouge">system</code>.</p>

<p><strong>REVRB-LANTERN-10:</strong> <code class="language-plaintext highlighter-rouge">set nfs download</code> passes unsanitized user input into a call to <code class="language-plaintext highlighter-rouge">system</code>.</p>

<p><strong>REVRB-LANTERN-11:</strong> <code class="language-plaintext highlighter-rouge">set script schedule</code> passes unsanitized user input into a call to <code class="language-plaintext highlighter-rouge">system</code>.</p>

<h2 id="footnote-concerning-the-slc9000">Footnote Concerning the SLC9000</h2>

<p>It is our belief that the SLC9000 may be vulnerable to the web management portal vulnerabilities disclosed here, but we are resource-constrained from validating them.</p>

<p>We first asked Lantronix about shared code concerning the SLC9000 in June. Our initial inquiry was based on the SLC9000 User Guide which demonstrated identical CLI commands to the SLC8000, and even retained the PDF meta title “SLC8000 Advanced Console Server User Guide”.<sup id="fnref:slc9k-userguide" role="doc-noteref"><a href="#fn:slc9k-userguide" class="footnote" rel="footnote">21</a></sup> Lantronix’s response was to remove any mention of the SLC9000 from our coordination document, stating that the SLC9000 was “not yet in customer hands”.</p>

<p>In August, after they had published firmware version 9.7.0.1 for the SLC9000, we disclosed REVRB-LANTERN-13, 14, and 15 to them, and asked again how we should handle these findings in relation to the SLC9000. Instead of answering, Lantronix stated they had “serious concerns” about our assertions of shared code from June, prior to the device’s release, calling it “a bit disturbing”. After we assured them that we did not access anything non-public, and explained our reasoning for expecting the web server to be the same between them, Lantronix’s response was, “Consistent user experience does not imply shared code base”.</p>

<p>It was also around this time that they responded to our notice of a firm disclosure date with “The disclosure shall be limited to SLC8000, EMG8500, and EMG7500”. We followed up and asked whether they meant their own disclosure or ours, to which they responded, “We believe your publication should be limited to SLC8000, EMG8500, and EMG7500.”</p>

<p>In early September, Shodan scanned an SLC9000, providing the HTML response of its login page. The following is a diff between the login pages of the SLC8000 and SLC9000.</p>

<div class="language-diff highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="gd">--- a/slc8000.html
</span><span class="gi">+++ b/slc9000.html
</span><span class="p">@@ -1,105 +1,105 @@</span>
 &lt;!DOCTYPE html PUBLIC "-//W3C//Dtd html 4.0 transitional//EN"&gt;
 &lt;htmL&gt;
 &lt;head&gt;
<span class="gd">-&lt;title&gt;Lantronix SLC 8016&lt;/title&gt;
</span><span class="gi">+&lt;title&gt;Lantronix SLC9016&lt;/title&gt;
</span> 
 &lt;meta http-equiv=Content-Type content="text/html; charset=iso-8859-1"&gt;
 
 &lt;link href="images/style.css" type=text/css rel=stylesheet&gt;
 
 &lt;style&gt;
 &lt;!--
 html { visibility: hidden }
 --&gt;
 &lt;/style&gt;
 
 &lt;/head&gt;
 
 &lt;script&gt;
 &lt;!--
 
 function applyForm(id)
 {
   var login = document.getElementById('text_login');
   var pass = document.getElementById('text_pass');
   if (login.value == "")
   {
     alert("Login: required field.");
     login.focus();
     return false;
   }
   if (pass.value == "")
   {
     alert("Password: required field.");
     pass.focus();
     return false;
   }
   document.theform.submit();
   return true;
 } // applyForm
 
 window.onload = function() {
   var login = document.getElementById('text_login');
   if (self == top) {
     document.documentElement.style.visibility = 'visible';
   } else {
     top.location = self.location;
   }
   login.focus();
 }
 
 --&gt;
 &lt;/script&gt;
 
 &lt;body class="auth" leftMargin=0 topMargin=0 marginwidth=0 marginheight=0&gt;
 
 &lt;div class=authTopbar&gt;
   &lt;div class=logo&gt;
     &lt;a href="http://www.lantronix.com"&gt;&lt;img src="images/ltrx_logo_new.gif" border=0&gt;&lt;/a&gt;
   &lt;/div&gt;
<span class="gd">-  &lt;div class=product&gt;SLC 8016&lt;/div&gt;
</span><span class="gi">+  &lt;div class=product&gt;SLC9016&lt;/div&gt;
</span> &lt;/div&gt;
 &lt;div class=authLine&gt;&lt;/div&gt;
 
 &lt;form name=theform method=post autocomplete="off" onSubmit="return applyForm()"&gt;
 
 &lt;div style="height: 350px" align=center&gt;
   &lt;div&gt;&lt;/div&gt;
   &lt;div class=loginBanner&gt;
 Welcome to the SLC
       &lt;br&gt;&amp;nbsp;
   &lt;/div&gt;
<span class="gd">-  &lt;div class=loginTitle&gt;Login to SLC 8016&lt;/div&gt;
</span><span class="gi">+  &lt;div class=loginTitle&gt;Login to SLC9016&lt;/div&gt;
</span>   &lt;div class=authPortletGroup&gt;
     &lt;div class=portletContent style="background-color: #f2f2f2"&gt;
       &lt;table width=370 border=0&gt;
         &lt;tr&gt;
           &lt;td class=authPadding align=center colspan=2&gt;
           &lt;/td&gt;
         &lt;/tr&gt;
         &lt;tr&gt;
           &lt;td class="fieldName authPadding"&gt;Login:&lt;/td&gt;
<span class="gd">-&lt;td class="fieldValue authPadding"&gt;&lt;input class="fieldValue" type=text name=slcloginS0E20260c28116-29547 id="text_login" size=32 maxlength=32 value=""&gt;&lt;/td&gt;
</span><span class="gi">+&lt;td class="fieldValue authPadding"&gt;&lt;input class="fieldValue" type=text name=slcloginS0S00261q59716-69109 id="text_login" size=32 maxlength=32 value=""&gt;&lt;/td&gt;
</span>         &lt;/tr&gt;
         &lt;tr&gt;
           &lt;td class="fieldName authPadding"&gt;Password:&lt;/td&gt;
<span class="gd">-&lt;td class="fieldValue authPadding"&gt;&lt;input class="fieldValue" type=password name=slcpasswordS0E20260c28116-29547 id="text_pass" size=32 maxlength=64 value=""&gt;&lt;/td&gt;
</span><span class="gi">+&lt;td class="fieldValue authPadding"&gt;&lt;input class="fieldValue" type=password name=slcpasswordS0S00261q59716-69109 id="text_pass" size=32 maxlength=64 value=""&gt;&lt;/td&gt;
</span>         &lt;/tr&gt;
         &lt;tr&gt;
           &lt;td class="authPadding" align=center colspan=2&gt;
             &lt;input class=pushButton type=submit value="Login" onClick="return applyForm()"&gt;
           &lt;/td&gt;
         &lt;/tr&gt;
       &lt;/table&gt;
     &lt;/div&gt;
   &lt;/div&gt;
   &lt;div&gt;&amp;nbsp;&lt;br&gt;&amp;nbsp;&lt;/div&gt;
 
   &lt;div class="authLine authFooter"&gt;
<span class="gd">-  &amp;copy; 2003-2023 Lantronix, Inc.
</span><span class="gi">+  &amp;copy; 2003-2026 Lantronix, Inc.
</span>   &lt;/div&gt;
 &lt;/div&gt;
 
 &lt;/form&gt;
 &lt;/body&gt;
 &lt;/html&gt;
</code></pre></div></div>

<p>The <code class="language-plaintext highlighter-rouge">name</code> properties of the changed input tags, in our research, implicate portions of code responsible for REVRB-LANTERN-13 and 14. Using code from the SLC8000, we were able to reverse the transposition on the ‘name’ property of the SLC8000’s homepage to “S??8016-092126022547” - this maps to &lt;model&gt;-&lt;timestamp:MMddyyhhmmss&gt; (though the second and third characters of the model get overwritten). Using the same code on the ‘name’ property for the SLC9000, we obtain “S??9016-090726165109”, indicating that code responsible for this dynamic, authentication-tied server response is consistent with shared code between the SLC8000 and SLC9000.</p>

<p>On 18 September, Lantronix published firmware updates for the EMG7500, EMG8500, SLC8000, and SLC9000, each citing “security vulnerabilities” in their respective release notes. We do not claim to know what vulnerabilities were patched on the SLC9000.</p>

<p>If you own an SLC9000 and would like to coordinate further research, please reach out to research@revrb.net.</p>

<h2 id="gnu-general-public-license-gpl-code">GNU General Public License (GPL) Code</h2>

<p>We at RE/VRb believe that code obtained, modified, and/or monetized under GNU General Public Licensing makes the world go ‘round.<sup id="fnref:linux-share" role="doc-noteref"><a href="#fn:linux-share" class="footnote" rel="footnote">22</a></sup> As a matter of practice, we ask for GPL-covered code whenever we identify it in an investigation, and we aim to share it.</p>

<p>During this investigation, we asked Lantronix multiple times, as far back as April, for code covered by the GPLv2. Despite frequent communication on other topics, Lantronix did not answer for the location or availability of source code for GPL-covered binaries until late August, when we received this response: “Why is this needed?”</p>

<p>We at RE/VRb make no claims about Lantronix’s legal compliance with any version of the GPL - only that we identified GPL-covered code on devices we obtained for this investigation, that we asked repeatedly for the corresponding source code or a path to obtain it, and that we have received none - and therefore have none to share.</p>

<h2 id="future-work">Future Work</h2>

<p>While RE/VRb stands by this report and the work that generated it, we don’t believe this report to be a comprehensive audit of these devices. The code patterns that spawned these findings are still prevalent elsewhere - below is a table showing the number of potentially unsafe libc calls in the newest version of the SLC8000’s web management binary, per Ghidra’s automated analysis and based largely on GitHub’s banned.h:</p>

<table>
  <thead>
    <tr>
      <th>libc Call</th>
      <th>Number of Cross-References</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strcpy</code></td>
      <td>499</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strcat</code></td>
      <td>372</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strncpy</code></td>
      <td>37</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strncat</code></td>
      <td>2</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strtok</code></td>
      <td>120</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">strtok_r</code></td>
      <td>8</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">sprintf</code></td>
      <td>433</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">system</code></td>
      <td>146</td>
    </tr>
    <tr>
      <td><code class="language-plaintext highlighter-rouge">popen</code></td>
      <td>91</td>
    </tr>
  </tbody>
</table>

<p>These devices are still deeply interesting targets for security research.</p>

<h2 class="no_toc" id="corrections-and-coordination">Corrections and Coordination</h2>

<p>We can be reached concerning corrections to this advisory at research@revrb.net.</p>

<h2 class="no_toc" id="citations">Citations</h2>
<div class="footnotes" role="doc-endnotes">
  <ol>
    <li id="fn:slb-eol" role="doc-endnote">
      <p>Lantronix, <a href="https://cdn.lantronix.com/wp-content/uploads/pdf/PCN-881-SLB-PRODUCT-FAMILY-DISCONTINUATION-NOTICE.pdf"><em>Product Discontinuation Notice - December 18, 2023</em></a> <a href="#fnref:slb-eol" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:sambanova-slc8000" role="doc-endnote">
      <p>SambaNova, <a href="https://docs.sambanova.ai/docs/en/sambastack/resources/thirdparty"><em>Third-party Components</em></a> <a href="#fnref:sambanova-slc8000" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:sambanova-slc9000" role="doc-endnote">
      <p>Roic AI, <a href="https://www.roic.ai/quote/LTRX/transcripts/2026-year/4-quarter"><em>Lantronix, Inc. (LTRX) Q4 FY2026 Earnings Call Transcript - August 26, 2026</em></a> <a href="#fnref:sambanova-slc9000" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:usdoe-argonne" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/blog/argonne-national-laboratory-enhances-ai-testbed-for-scientific-research"><em>Argonne National Laboratory Deploys SambaNova Suite to Advance AI Inference In Science Research</em></a> <a href="#fnref:usdoe-argonne" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:usdoe-oakridge" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/blog/oak-ridge-national-laboratory-deploy-sambanova-suite-for-ai-for-science"><em>Oak Ridge National Laboratory Deploys SambaNova Suite, Enabling Energy-Efficient AI Inference for Science</em></a> <a href="#fnref:usdoe-oakridge" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:usdoe-losalamos" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/blog/los-alamos-national-laboratory-expands-partnership-with-sambanova"><em>Los Alamos National Laboratory expands partnership with SambaNova</em></a> <a href="#fnref:usdoe-losalamos" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:usdoe-lawrencelivermore" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/press/sambanova-and-lawrence-livermore-national-laboratory-scale-up-collaboration-to-accelerate-ai-for-science"><em>SambaNova and Lawrence Livermore National Laboratory Scale Up Collaboration to Accelerate AI for Science</em></a> <a href="#fnref:usdoe-lawrencelivermore" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:hpc-tacc" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/blog/tacc-deploys-sambanova-suite-ai-inference-for-scientific-research"><em>Texas Advanced Computing Center Deploys SambaNova Suite, Enabling AI Inference for Science</em></a> <a href="#fnref:hpc-tacc" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:hpc-riken" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/ja/press/sambanova-systems-to-deliver-sambanova-datascale-to-riken"><em>SambaNova to provide SambaNova DataScale to RIKEN</em></a> <a href="#fnref:hpc-riken" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:sambanova-sovai" role="doc-endnote">
      <p>SambaNova, <a href="https://sambanova.ai/press/sambanova-powers-the-ai-backbone-for-three-sovereign-ai-providers-across-australia-europe-and-the-u.k"><em>SambaNova Powers the AI Backbone for Three Sovereign AI Providers Across Australia, Europe and the UK</em></a> <a href="#fnref:sambanova-sovai" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:disa-csciii" role="doc-endnote">
      <p>DISA CSC III, <a href="https://govtribe.com/file/government-file/pws-appendix-1-comm-equipment-inventory-dot-xlsx"><em>PWS Appendix 1 - Comm Equipment Inventory.xlsx</em> (GovTribe mirror)</a> <a href="#fnref:disa-csciii" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:ltrx-2019-q2" role="doc-endnote">
      <p>Roic AI, <a href="https://www.roic.ai/quote/LTRX/transcripts/2019-year/2-quarter"><em>Lantronix, Inc. (LTRX) Q2 FY2019 Earnings Call Transcript</em></a> <a href="#fnref:ltrx-2019-q2" class="reversefootnote" role="doc-backlink">&#8617;</a> <a href="#fnref:ltrx-2019-q2:1" class="reversefootnote" role="doc-backlink">&#8617;<sup>2</sup></a></p>
    </li>
    <li id="fn:moto-contract" role="doc-endnote">
      <p>Commonwealth of Pennsylvania / Motorola Solutions, <a href="https://www.emarketplace.state.pa.us/FileDownload.aspx?file=4400027237%5CChangeNotice.pdf">ASTRO contract pricing and equipment descriptions</a> <a href="#fnref:moto-contract" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:telecom-giant" role="doc-endnote">
      <p>Lantronix, <a href="https://www.lantronix.com/resources/application-spotlights/enabling-robust-data-center-infrastructure-access-management-for-telecom-giant/"><em>Enabling Robust Data Center Infrastructure Access &amp; Management for Telecom Giant</em></a> <a href="#fnref:telecom-giant" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:cable-giant" role="doc-endnote">
      <p>Lantronix, <a href="https://www.lantronix.com/resources/application-spotlights/ensuring-highest-levels-reliability-service-cable-video-streaming-band-management/"><em>Ensuring the Highest Levels of Reliability and Service for Cable and Video Streaming</em></a> <a href="#fnref:cable-giant" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:battle-card" role="doc-endnote">
      <p>Lantronix, <a href="https://www.lantronix.com/wp-content/uploads/pdf/SLC8000_BattleCard_Final_021216-1.pdf"><em>Why the SLC 8000 is the Only Advanced Modular Console Manager for Enterprise</em></a> <a href="#fnref:battle-card" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:select-customers" role="doc-endnote">
      <p>Lantronix, <a href="https://www.lantronix.com/wp-content/uploads/pdf/LTRX-Q2-Prelim-Needham-IR-Preso-Jan-2017.pdf"><em>Investor Presentation - 19th Annual Needham Growth Conference</em></a> <a href="#fnref:select-customers" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:u-cambridge" role="doc-endnote">
      <p>Lantronix, <a href="https://cdn.lantronix.com/wp-content/uploads/pdf/Univ.-of-Cambridge-CS_FNL_no-bleed.pdf"><em>Lantronix Out-of-Band Solutions Power University of Cambridge</em></a> <a href="#fnref:u-cambridge" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:ltrx-2016-q1" role="doc-endnote">
      <p>Roic AI, <a href="https://www.roic.ai/quote/LTRX/transcripts/2016-year/1-quarter"><em>Lantronix, Inc. (LTRX) Q1 FY2016 Earnings Call Transcript</em></a> <a href="#fnref:ltrx-2016-q1" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:aloha-observatory" role="doc-endnote">
      <p>Lantronix, <a href="https://www.lantronix.com/newsroom/press-releases/lantronix-highlights-management-solutions-data-center-world/"><em>Lantronix Highlights Out of Band Management Solutions at Data Center World</em></a> <a href="#fnref:aloha-observatory" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:slc9k-userguide" role="doc-endnote">
      <p>Lantronix, <a href="https://cdn.lantronix.com/wp-content/uploads/pdf/PMD-00347A-SLC9K-UG-release.pdf"><em>SLC 9000 Advanced Console Server User Guide</em></a> <a href="#fnref:slc9k-userguide" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
    <li id="fn:linux-share" role="doc-endnote">
      <p>w3techs.com, <a href="https://w3techs.com/technologies/details/os-linux"><em>Usage Statistics and Market Share of Linux for Websites, September 2026</em></a> <a href="#fnref:linux-share" class="reversefootnote" role="doc-backlink">&#8617;</a></p>
    </li>
  </ol>
</div>]]></content><author><name></name></author><category term="security" /><category term="lantronix" /><category term="cve" /><category term="ot" /><summary type="html"><![CDATA[RE/VRb LLC conducts independent research to improve cyber infrastructure security. The following report details research conducted without contract or bounty, representing over four months of discovery and coordination by a single researcher. You can support our ongoing efforts here.]]></summary></entry></feed>