CVE-2026-91191: Lantronix G520 Series Cellular Gateway Improper Verification of Cryptographic Signature
The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Lantronix G520 Series Cellular Gatewayto a version that resolves this vulnerability.Fixed in 2.6.0.7R6
Event History
Frequently Asked Questions
What access or delivery path would an attacker need to exploit this issue?
An attacker would need to be able to supply a malicious software package to the device's package restoration or installation process. Exploitation also requires user interaction, as reflected by the UI:R vector.
Does re-enabling package signature verification fully mitigate the risk?
No. The production private key is publicly distributed in the SDK, and its corresponding public key is trusted by stable and beta firmware builds. An attacker can use that key to create packages with signatures the device will continue to accept.
What is the likely impact if a malicious package is installed?
A malicious package may execute arbitrary code with root privileges during installation. This can affect confidentiality, integrity, and availability of the gateway.
Which package source is involved during boot?
During boot, the stock done function disables OPKG signature verification before optional packages are restored from a writable, unsigned feed. This creates a path for unauthorized packages to be accepted during restoration.