// Lantronix G520 / case study

Update integrity and package authenticity in an industrial gateway

I reported two vulnerabilities affecting the Lantronix G520 Series Cellular Gateway. CISA coordinated the disclosure and published ICSA-26-272-01 on September 29, 2026, crediting me as the researcher. Lantronix addressed the reported issues in firmware 2.6.0.7R6.

Published | CISA ICSA-26-272-01 | 2 CVEsDisclosure-safe summary
Trust-boundary path
01Untrusted update inputs
02Update and package trust controls
03Administrative or root execution

Project and affected component

Software-update metadata handling, the management web interface, and package-authenticity controls.

Security boundary

Externally supplied update information and software packages must remain untrusted until they have passed the controls required for administrative display or privileged installation.

Vulnerability class

CVE-2026-84409: CWE-79, cross-site scripting. CVE-2026-91191: CWE-347, improper verification of cryptographic signatures. CISA assigns each vulnerability a CVSS 3.1 score of 7.5, High.

CVE-2026-84409

Update metadata retrieved over HTTP could reach the management interface without safe handling. CISA describes how attacker-influenced metadata could execute within the administrative context under the documented conditions.

CVE-2026-91191

Weaknesses in package-signature enforcement and signing-key protection undermined package authenticity. CISA describes the potential for attacker-supplied packages to execute code with root privileges during installation.

Root cause

The advisory records two separate trust failures: unsafe handling of update metadata in the administrative interface and ineffective package-authenticity enforcement. The two CVEs do not depend on a mandatory exploit chain.

Public evidence

The public CISA advisory documents both vulnerabilities, identifies firmware 2.6.0.4R6_stable as affected, credits Ievgen Bondarenko, and records remediation in firmware 2.6.0.7R6. This page does not claim an independent patch retest.

Practical impact

Under the conditions documented by CISA, the vulnerabilities could permit arbitrary code execution, including root-level execution through package installation. Exploitation depends on the relevant update-metadata or package-supply conditions.

Disclosure status

Coordinated through CISA. Public advisory ICSA-26-272-01 was published on September 29, 2026, with researcher credit to Ievgen Bondarenko.

Remediation

CISA reports that Lantronix addressed the issues in firmware 2.6.0.7R6. The advisory identifies 2.6.0.4R6_stable as affected.

Sector context

CISA lists Transportation Systems, Energy, and Water and Wastewater Systems as the product's critical-infrastructure sector context. This describes the product's deployment context, not research performed on operational infrastructure.

Public references