Skip to content
Security & Trust

Two flaws in Lantronix gateways let attackers run root code through updates

CISA lists two flaws in G520 cellular gateways. In one, the update signing key sat in a public developer kit.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Two flaws in Lantronix gateways let attackers run root code through updates

AI-generated image for WebPulse. About our images

Key finding

Vulnerabilities in the advisory: 2 (Source: CISA ICS advisory ICSA-26-272-01 (September 29, 2026))

A software update is a promise. The device asks for new code. The code must prove it came from the maker. If that proof can be forged, the update channel becomes an easy way to take over a device.

That is the lesson in a CISA advisory published on September 29. It covers the Lantronix G520 Series Cellular Gateway. It describes two weaknesses. Both concern which updates the device chooses to trust. Each could let an attacker run code as root. Root is the highest level of control on a device.

What CISA reported

The advisory is numbered ICSA-26-272-01. It lists the affected firmware as G520 Series 2.6.0.4R6_stable. Two CVEs apply to that version: CVE-2026-84409 and CVE-2026-91191. Ievgen Bondarenko reported the issues to CISA.

Lantronix fixed the problems in firmware release 2.6.0.7R6. CISA says no public exploitation aimed at these flaws had been reported to it. That was true when the advisory was written. It says nothing about later.

2
Vulnerabilities in the advisory
Source: CISA ICS advisory ICSA-26-272-01 (September 29, 2026)
2.6.0.7R6
Firmware release that addresses them
Source: CISA ICS advisory ICSA-26-272-01 (September 29, 2026)

How the first weakness works

The gateway checks for updates over plain HTTP. That means the connection is not encrypted. The device saves part of the update information it receives. Later, a management interface sends that saved text back to the device's web page.

The page puts that text straight into itself as HTML. So text written by an attacker can run as a script. CISA calls this cross-site scripting (CWE-79).

The same web interface can also run system commands as root. Put the two together and the advisory's conclusion follows. An attacker who can shape the update information could run any code with the device's administrative powers.

How the second weakness works

The second issue is about proving a software package is genuine. CISA calls it improper verification of a cryptographic signature (CWE-347). It has two parts.

First, at startup, a stock boot function turns off signature checking in the package manager settings (OPKG). It then restores optional packages from a writable feed. That feed carries no signatures.

Second, the production private key is inside the SDK that Lantronix distributes publicly. An SDK is a developer toolkit. The device trusts the matching public key in both its stable and beta firmware.

The advisory says either problem undermines package authenticity. Together, they let an attacker supply packages that look valid to the system.

Turning signature checks back on would not fix this. The exposed key would still let an attacker sign packages the device accepts. Installing such a package could give the attacker root access.

The idea: a signature is only as strong as the key's secrecy

Think of a notary's stamp left on the front desk. Every document still carries a perfect stamp. But the stamp no longer means anything.

Code signing works the same way. It protects a device only while the private key stays private. A key shipped in a public SDK cannot do that job. The device sees a valid signature, so it cannot tell anything is wrong.

This shows why patching is only part of the answer. Buyers usually ask whether a device checks its updates. The harder question is who could produce a valid signature.

Where these devices are used

CISA lists three affected sectors: Transportation Systems, Energy, and Water and Wastewater Systems. The company is headquartered in the United States. The advisory does not say how many devices are deployed or where.

CISA's general advice for control system devices applies here. Keep them off the internet. Place them behind firewalls, away from business networks.

3
Critical infrastructure sectors listed
Source: CISA ICS advisory ICSA-26-272-01 (September 29, 2026)

What leaders should ask their teams

First, do we run any G520 Series gateways? Which firmware are they on? The advisory lists version 2.6.0.4R6_stable. The fix is release 2.6.0.7R6.

Second, can any of them be reached from the internet? CISA advises minimising that exposure. Where remote access is needed, it suggests VPNs. It also warns that VPNs can have flaws. A VPN is only as secure as the devices connected to it.

Third, ask every device vendor where its signing keys are kept. Ask how updates are checked. A written answer is a fair request in any purchase.

A signed update should be evidence that the maker sent it. In this advisory, the key that proves it was left where anyone could take it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-84409 CVE-2026-91191
Share this insight