{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/g520-series-cellular-gateway-2.6.0.4r6_stable/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["G520 Series Cellular Gateway (2.6.0.4R6_stable)"],"_cs_severities":["high"],"_cs_tags":["ics","cve","firmware-vulnerability","remote-code-execution"],"_cs_type":"threat","_cs_vendors":["Lantronix"],"content_html":"\u003cp\u003eLantronix G520 Series Cellular Gateway firmware version 2.6.0.4R6_stable contains two critical vulnerabilities that expose devices to full remote compromise. CVE-2026-84409 relates to an insecure update mechanism that fetches metadata over unencrypted HTTP, which is subsequently rendered in a web interface without proper neutralization, leading to Cross-Site Scripting (XSS). An attacker can leverage this to execute arbitrary commands as root within the administrative context.\u003c/p\u003e\n\u003cp\u003eAdditionally, CVE-2026-91191 allows for the installation of malicious software packages due to improper signature verification and the inclusion of production private keys within the public SDK. By exploiting these flaws, an attacker can bypass package integrity checks and deploy arbitrary, malicious code with root-level access during the device boot or update process. These vulnerabilities pose significant risks to critical infrastructure sectors, including energy, water, and transportation, where such gateways are deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation could result in complete loss of device control, persistent access for attackers, and the ability to pivot into sensitive operational networks. As these devices are typically deployed at the edge of industrial networks, compromise could lead to operational disruption, data exfiltration, or the unauthorized manipulation of industrial control processes. There are no reported cases of active exploitation in the wild as of the date of publication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Lantronix G520 Series Cellular Gateways to firmware version 2.6.0.7R6 immediately to remediate both CVE-2026-84409 and CVE-2026-91191.\u003c/li\u003e\n\u003cli\u003eIsolate cellular gateways from the public internet using firewalls; ensure that management interfaces are only accessible via secure, authenticated VPN tunnels.\u003c/li\u003e\n\u003cli\u003eImplement egress traffic monitoring for gateway management traffic to identify connections to untrusted or unauthorized update servers.\u003c/li\u003e\n\u003cli\u003eDisable unneeded services on gateway devices to reduce the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T16:25:38Z","date_published":"2026-09-29T16:25:38Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lantronix-gateway/","summary":"Multiple vulnerabilities in Lantronix G520 Series Cellular Gateway firmware allow remote, unauthenticated attackers to execute arbitrary code with root privileges by manipulating update metadata or injecting unsigned malicious packages.","title":"Critical Vulnerabilities in Lantronix G520 Series Cellular Gateway","url":"https://feed.craftedsignal.io/briefs/2026-09-lantronix-gateway/"}],"language":"en","title":"CraftedSignal Threat Feed - G520 Series Cellular Gateway (2.6.0.4R6_stable)","version":"https://jsonfeed.org/version/1.1"}