CISA Warns of Critical Vulnerabilities in Lantronix G520 Cellular Gateways
CISA has issued an advisory detailing two critical vulnerabilities in Lantronix G520 Series Cellular Gateway devices, versions 2.6.0.4R6_stable, that could allow for arbitrary code execution with root privileges.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting significant security flaws affecting Lantronix G520 Series Cellular Gateway devices. Specifically, version 2.6.0.4R6_stable is vulnerable to two critical issues, CVE-2026-84409 and CVE-2026-91191, which could enable attackers to gain root-level control over the affected devices.
CVE-2026-84409 stems from an unencrypted update mechanism and improper HTML sanitization within the device's web interface. The gateway retrieves software update metadata over an unencrypted HTTP connection. This metadata is later stored and then directly inserted into a JSON response and displayed on the web interface without proper sanitization. An attacker who can influence this metadata could exploit this flaw to inject malicious script content, leading to arbitrary code execution with administrative privileges.
Compounding the risk, CVE-2026-91191 involves flaws in signature verification for software packages and the exposure of a production private key. The device's update mechanism incorrectly verifies the authenticity of software packages. During the boot process, signature verification is disabled, allowing unauthorized packages to be installed. Furthermore, the publicly distributed SDK contains the production private key, which is trusted by the firmware. This allows an attacker to craft malicious packages with valid signatures, enabling them to execute arbitrary code with root privileges during the installation process, even if signature enforcement is later restored.
Successful exploitation of either vulnerability could allow an attacker to replace legitimate software with malicious versions and execute arbitrary code with the highest level of privilege on the device. The potential impact is severe, as these gateways are deployed in critical infrastructure sectors including transportation systems, energy, and water and wastewater systems, with a global presence.
Lantronix has acknowledged these vulnerabilities and has released version 2.6.0.7R6 of the G520 Series firmware to address the issues. Users are strongly advised to update their devices to the latest version as soon as possible to mitigate the risks. Further details and the updated firmware can be found on Lantronix's website and their vulnerability library.
CISA recommends that organizations minimize network exposure for all control system devices, ensuring they are not accessible from the internet. Isolating control system networks behind firewalls and using secure remote access methods like VPNs are crucial defensive measures. Organizations should also conduct thorough impact and risk assessments before implementing any defensive strategies.
The vulnerabilities, tracked under CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-347 (Improper Verification of Cryptographic Signature), carry high CVSS v3.1 base scores of 7.5, indicating a significant risk. The CVSS v4.0 scores are also high at 7.7. These advisories underscore the ongoing need for vigilance in securing industrial control systems against increasingly sophisticated threats.