Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Update‑Mechanism Flaws (CVE‑2026‑84409, CVE‑2026‑91191) Enable Remote Code Execution on Lantronix G520 Cellular Gateways

CISA has issued an advisory for Lantronix G520 Series Cellular Gateways, identifying two CVEs that let an attacker tamper with update metadata over unencrypted HTTP and bypass signature verification, leading to arbitrary code execution with root privileges. The flaws affect devices deployed in transportation, energy, and water sectors worldwide, raising concerns for control‑system integrity and audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical Update‑Mechanism Flaws (CVE‑2026‑84409, CVE‑2026‑91191) Enable Remote Code Execution on Lantronix G520 Cellular Gateways

What It Is – CISA’s advisory (ICSA‑26‑272‑01) reports two high‑severity vulnerabilities in the Lantronix G520 Series Cellular Gateway. CVE‑2026‑84409 is an XSS/metadata injection flaw in the device’s update‑metadata handling; CVE‑2026‑91191 is an improper verification of the firmware‑image cryptographic signature. Together they allow an attacker to tamper with update data and execute arbitrary code with root privileges.

Exploitability – Both flaws are exploitable over an unencrypted HTTP channel without prior authentication. Public proof‑of‑concept code has been released, and the CVSS v3 base score is 7.5 (High).

Affected Products – Lantronix G520 Series Cellular Gateway, firmware version 2.6.0.4R6_stable. The devices are deployed worldwide in transportation, energy, and water‑and‑wastewater control‑system environments.

Why It Matters for Trust & Control Assurance

  • Software‑update integrity is a core control objective; a break here undermines the evidence you need to prove a defensible change‑management process.
  • Continuous monitoring of firmware signatures and transport security provides audit‑ready proof that only authorized code runs on critical‑infrastructure assets.
  • Enterprise buyers increasingly demand demonstrable assurance that supply‑chain devices enforce cryptographic verification and encrypted update channels.

Recommended Actions

  • Deploy Lantronix’s security patches for both CVEs immediately.
  • Enforce TLS (or other encrypted transport) for all update‑metadata communications.
  • Verify cryptographic signatures of firmware before installation; reject unsigned or mismatched images.
  • Update your asset inventory and collect evidence of patch status for audit purposes.
  • Map the “software update integrity” control to the Verisq Common Framework (VCF) and capture continuous compliance evidence.

Source: CISA Advisory – ICSA‑26‑272‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →