🚨 #ALERT — LANTRONIX G520 UPDATE-CHAIN FLAWS CAN ENABLE ATTACKER-CONTROLLED SOFTWARE TO EXECUTE AS ROOT
September 29, 2026
DISCLOSED BY:
CISA ICS / Lantronix
PRODUCT:
Lantronix G520 Series Cellular Gateway
CVE:
CVE-2026-84409
CVE-2026-91191
AFFECTED VERSIONS:
G520 Series 2.6.0.4R6_stable
FIXED VERSION:
2.6.0.7R6 or later
IMPACT:
CVE-2026-84409 allows attacker-influenced update metadata retrieved over unencrypted HTTP to be rendered as active content in the administrative origin, which also exposes root-capable command functionality.
CVE-2026-91191 undermines software-update authenticity. Lantronix states that signature enforcement can be disabled during restore and that the production private key was included in a publicly distributed SDK, allowing attacker-generated packages to appear trusted and potentially execute arbitrary code as root during installation.
EXPLOITATION STATUS:
VULNERABILITIES CONFIRMED
NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED
URGENT ACTION:
Upgrade to 2.6.0.7R6 or later. Restrict management/update paths to trusted networks and review package/update history for unauthorized software or configuration changes.
SOURCE:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01
VENDOR — CVE-2026-84409:
https://www.lantronix.com/security-advisories/cve-2026-84409/
VENDOR — CVE-2026-91191:
https://www.lantronix.com/security-advisories/cve-2026-91191/
#CyberSecurity #ThreatIntel #Lantronix #SupplyChain #FirmwareSecurity #Root #CVE