CVE-2026-84409: Lantronix G520 Series Cellular Gateway Cross-site Scripting
The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix G520 Series Cellular Gatewayto a version that resolves this vulnerability.Fixed in 2.6.0.7R6
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker must be able to influence the software-update metadata retrieved by the gateway over unencrypted HTTP. Exploitation also requires a user to view the update information in the device web interface, where the stored metadata is inserted as HTML.
What could successful exploitation allow?
Attacker-controlled metadata can execute script in the administrative context of the device web interface. Because that authenticated origin includes an interface capable of running system-level commands with root privileges, this can lead to arbitrary code execution on the gateway.
How can exposure be reduced if an update is not immediately available?
Reduce the opportunity for update metadata to be modified in transit by preventing or tightly controlling the gateway's use of unencrypted HTTP for update metadata retrieval. Limit access to the management interface and avoid viewing update information when metadata integrity cannot be trusted.