CVE-2026-84409: Lantronix G520 Series Cellular Gateway Cross-site Scripting

Published Sep 29, 2026
·
Updated

The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.

Affected Software

1 affected component
Lantronix G520 Series Cellular Gateway

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Lantronix G520 Series Cellular Gateway to a version that resolves this vulnerability.

    Fixed in 2.6.0.7R6

Event History

Sep 29, 2026
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker must be able to influence the software-update metadata retrieved by the gateway over unencrypted HTTP. Exploitation also requires a user to view the update information in the device web interface, where the stored metadata is inserted as HTML.

2

What could successful exploitation allow?

Attacker-controlled metadata can execute script in the administrative context of the device web interface. Because that authenticated origin includes an interface capable of running system-level commands with root privileges, this can lead to arbitrary code execution on the gateway.

3

How can exposure be reduced if an update is not immediately available?

Reduce the opportunity for update metadata to be modified in transit by preventing or tightly controlling the gateway's use of unencrypted HTTP for update metadata retrieval. Limit access to the management interface and avoid viewing update information when metadata integrity cannot be trusted.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203