
🔴 Lantronix G520 cellular gateways vulnerable to root-level code execution Lantronix G520 Series Cellular Gateway version 2.6.0.4R6_stable contains two critical vulnerabilities (CVE-2026-84409, CVE-2026-91191) allowing attackers to execute arbitrary code with root privileges on devices deployed worldwide in transportation, energy, and water systems. The device's update mechanism retrieves metadata over unencrypted HTTP and stores it without validation. An attacker able to influence update metadata can inject malicious script content into the web interface and execute system commands within administrative context.

