CVE-2026-91191

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-29: 209-29
Referenced assets3 URLs
Full discourse2 posts
  • NewsTongue@NewsTongueX

    🔴 Lantronix G520 cellular gateways vulnerable to root-level code execution Lantronix G520 Series Cellular Gateway version 2.6.0.4R6_stable contains two critical vulnerabilities (CVE-2026-84409, CVE-2026-91191) allowing attackers to execute arbitrary code with root privileges on devices deployed worldwide in transportation, energy, and water systems. The device's update mechanism retrieves metadata over unencrypted HTTP and stores it without validation. An attacker able to influence update metadata can inject malicious script content into the web interface and execute system commands within administrative context.

    0000032
    930 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — LANTRONIX G520 UPDATE-CHAIN FLAWS CAN ENABLE ATTACKER-CONTROLLED SOFTWARE TO EXECUTE AS ROOT September 29, 2026 DISCLOSED BY: CISA ICS / Lantronix PRODUCT: Lantronix G520 Series Cellular Gateway CVE: CVE-2026-84409 CVE-2026-91191 AFFECTED VERSIONS: G520 Series 2.6.0.4R6_stable FIXED VERSION: 2.6.0.7R6 or later IMPACT: CVE-2026-84409 allows attacker-influenced update metadata retrieved over unencrypted HTTP to be rendered as active content in the administrative origin, which also exposes root-capable command functionality. CVE-2026-91191 undermines software-update authenticity. Lantronix states that signature enforcement can be disabled during restore and that the production private key was included in a publicly distributed SDK, allowing attacker-generated packages to appear trusted and potentially execute arbitrary code as root during installation. EXPLOITATION STATUS: VULNERABILITIES CONFIRMED NO CONFIRMED IN-THE-WILD EXPLOITATION IDENTIFIED URGENT ACTION: Upgrade to 2.6.0.7R6 or later. Restrict management/update paths to trusted networks and review package/update history for unauthorized software or configuration changes. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01 VENDOR — CVE-2026-84409: https://www.lantronix.com/security-advisories/cve-2026-84409/ VENDOR — CVE-2026-91191: https://www.lantronix.com/security-advisories/cve-2026-91191/ #CyberSecurity #ThreatIntel #Lantronix #SupplyChain #FirmwareSecurity #Root #CVE

    0000034
    225 followersView on X

Explore more