Security1 publisher2 min readPublished
Lantronix cellular gateway turns tampered update metadata into root code, CISA says
CISA says two flaws in Lantronix's G520 cellular gateway let anyone who can tamper with its plain-HTTP update traffic run code as root. The gateways run in transportation, energy and water networks worldwide, and Lantronix has shipped a fix in firmware 2.6.0.7R6.
The Watch · Security desk

What happened
- At boot the gateway disables OPKG signature verification and then restores optional packages from a writable, unsigned feed.
- The publicly distributed SDK contains the production private key whose public key both stable and beta firmware trust.
- Ievgen Bondarenko reported the two vulnerabilities to CISA.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The update fetch runs over plain HTTP, so the update channel is part of the attack surface: an attacker who can rewrite that traffic controls what the admin page renders.
- capability A malicious package runs as root during installation, so control of the update feed means control of the gateway.
- decision With a firmware fix available, the operator choice is to patch or to isolate the gateways from the internet and business networks, as CISA advises.
The first path starts at the update fetch. The G520 pulls update metadata over an unencrypted HTTP connection and keeps parts of it [4]. A management interface later returns that stored value in a JSON response, and the page that displays update information writes it into the HTML unchanged, so metadata an attacker controls is treated as script [5]. CISA classes this as cross-site scripting, CWE-79 [7]. That script runs in the same authenticated origin that also exposes an interface for executing system commands as root, so the chain runs from injected metadata to arbitrary code in the device's administrative context [6]. Because the fetch is unencrypted, anyone who can rewrite that HTTP response on the wire can plant the payload.
The second path is about package trust. During boot, the stock done function turns off signature verification in the OPKG configuration, then restores optional packages from a writable, unsigned feed [8]. The publicly distributed SDK also contains the production private key, and the matching public key is trusted by both stable and beta firmware [9]. CISA says either issue alone undermines package authenticity, and that even if signature enforcement is restored, the exposed key still lets an attacker generate signatures the device will accept [10]. It labels this CWE-347 [12]. An attacker who can deliver a malicious package can run code as root during installation [11].
Both paths reach the outcome CISA states up front: replace software and run arbitrary code as root [1]. The affected build is 2.6.0.4R6_stable, tracked as CVE-2026-84409 and CVE-2026-91191 [2]. Where the firmware update cannot be applied at once, CISA's guidance is exposure control: keep the gateways off the internet, behind firewalls, and isolated from the business network [15].
What to watch
- Whether a proof-of-concept or in-the-wild exploitation surfaces for CVE-2026-84409 or CVE-2026-91191.
- Whether 2.6.0.7R6 rotates the exposed production key or only patches the fetch and rendering path, since the leaked key still signs trusted packages.
- Whether CISA or Lantronix quantifies how many G520 gateways are reachable from the internet in transportation, energy and water networks.