CVE-2026-91191: Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature

Published Sep 29, 2026
·
Updated

The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.

Affected Software

1 affected component
Lantronix G520 Series Cellular Gateway

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Lantronix G520 Series Cellular Gateway to a version that resolves this vulnerability.

    Fixed in 2.6.0.7R6

Event History

Sep 29, 2026
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What access or delivery path would an attacker need to exploit this issue?

An attacker would need to be able to supply a malicious software package to the device's package restoration or installation process. Exploitation also requires user interaction, as reflected by the UI:R vector.

2

Does re-enabling package signature verification fully mitigate the risk?

No. The production private key is publicly distributed in the SDK, and its corresponding public key is trusted by stable and beta firmware builds. An attacker can use that key to create packages with signatures the device will continue to accept.

3

What is the likely impact if a malicious package is installed?

A malicious package may execute arbitrary code with root privileges during installation. This can affect confidentiality, integrity, and availability of the gateway.

4

Which package source is involved during boot?

During boot, the stock done function disables OPKG signature verification before optional packages are restored from a writable, unsigned feed. This creates a path for unauthorized packages to be accepted during restoration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203