vuln-advisoryregulatorNewsThe Broadside2 min read

Lantronix G520 Gateways Hit by Two-Vector RCE Chain

An XSS flaw plus an exposed SDK private key means patching to 2.6.0.7R6 fixes the vector but doesn't restore trust in what already ran on older firmware.


TL;DR

CISA published two vulnerabilities in Lantronix G520 Series Cellular Gateways (CVE-2026-84409, CVE-2026-91191) affecting versions through 2.6.0.4R6_stable. The attack chain combines a stored-XSS vector in the update-metadata path with a signature-verification bypass, the production private key shipped in the publicly available SDK. Together they allow arbitrary code execution with root privileges. Organizations in transportation, energy, and water sectors running these gateways should move to firmware 2.6.0.7R6. The advisory doesn't address retroactive integrity verification for devices that already ran the vulnerable firmware.

Lantronix has shipped a fix, firmware 2.6.0.7R6, and that's where the good news ends. The two CVEs CISA published Tuesday aren't independent bugs so much as adjacent failures that compound into a trust-anchor problem for anyone operating G520 gateways in production.

CVE-2026-84409 is a stored cross-site scripting vulnerability in the update mechanism. The device fetches update metadata over unencrypted HTTP, stores portions of it, and later returns those values in a JSON response that the management web interface inserts into the page as HTML. An attacker who can influence that metadata gets script execution in the administrative context, and the same authenticated origin exposes an interface that runs system commands with root privileges.

CVE-2026-91191 is where it gets worse. The stock boot process disables OPKG signature verification before restoring optional packages from a writable, unsigned feed. And the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Any attacker who has the key (which is, again, in the public SDK) can sign packages the device will accept even if signature enforcement is restored.

The practical result: an attacker who controls the metadata path (CVE-2026-84409) can pivot to installing signed malicious packages (CVE-2026-91191) and land root-level code execution. The patched firmware closes both vectors.

What the advisory doesn't answer

For defense contractors and integrators who deployed G520 units in segmented OT environments, the operational question isn't just "did we patch." It's whether anything already ran on those devices that shouldn't have. The advisory offers no guidance on retroactive integrity verification, no re-keying procedure for the trust anchor, and no forensic indicators. A device that booted older firmware with signature verification disabled and a publicly known private key can't attest to its own history.

This is a pattern with Lantronix OT gear. CISA advisories across the past 18 months have covered OS command injection in the EDS5000 series (CVE-2025-67034 through -67038, CVSS 9.8, now on CISA's Known Exploited Vulnerabilities Catalog), missing authentication in XPort (CVE-2025-2567, CVSS 9.8), and XXE in Provisioning Manager (CVE-2025-7766). The G520 advisory continues a run of vulnerabilities clustered around update integrity, input validation, and authentication boundaries, the kind of issues that compound when the same firmware architecture spans product lines.

CISA reported no known public exploitation targeting these specific vulnerabilities. That's the default caveat, not a comfort. The SDK has been public; the attack chain doesn't require chaining zero-days, just two documented CVEs and access to materials Lantronix distributed.


Published ·Deep Fathom

Lantronix G520 Gateways Hit by Two-Vector RCE Chain — The Broadside