Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.
The following versions of Lantronix G520 Series Cellular Gateway are affected:
G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191)
Vendor
Equipment
Lantronix
Lantronix G520 Series Cellular Gateway
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Verification of Cryptographic Signature
Critical Infrastructure Sectors: Transportation Systems, Energy, Water and Wastewater Systems
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JS...