Critical Update‑Mechanism Flaws (CVE‑2026‑84409, CVE‑2026‑91191) Enable Remote Code Execution on Lantronix G520 Cellular Gateways
What It Is – CISA’s advisory (ICSA‑26‑272‑01) reports two high‑severity vulnerabilities in the Lantronix G520 Series Cellular Gateway. CVE‑2026‑84409 is an XSS/metadata injection flaw in the device’s update‑metadata handling; CVE‑2026‑91191 is an improper verification of the firmware‑image cryptographic signature. Together they allow an attacker to tamper with update data and execute arbitrary code with root privileges.
Exploitability – Both flaws are exploitable over an unencrypted HTTP channel without prior authentication. Public proof‑of‑concept code has been released, and the CVSS v3 base score is 7.5 (High).
Affected Products – Lantronix G520 Series Cellular Gateway, firmware version 2.6.0.4R6_stable. The devices are deployed worldwide in transportation, energy, and water‑and‑wastewater control‑system environments.
Why It Matters for Trust & Control Assurance
- Software‑update integrity is a core control objective; a break here undermines the evidence you need to prove a defensible change‑management process.
- Continuous monitoring of firmware signatures and transport security provides audit‑ready proof that only authorized code runs on critical‑infrastructure assets.
- Enterprise buyers increasingly demand demonstrable assurance that supply‑chain devices enforce cryptographic verification and encrypted update channels.
Recommended Actions
- Deploy Lantronix’s security patches for both CVEs immediately.
- Enforce TLS (or other encrypted transport) for all update‑metadata communications.
- Verify cryptographic signatures of firmware before installation; reject unsigned or mismatched images.
- Update your asset inventory and collect evidence of patch status for audit purposes.
- Map the “software update integrity” control to the Verisq Common Framework (VCF) and capture continuous compliance evidence.
Source: CISA Advisory – ICSA‑26‑272‑01