Lantronix gateway SDK shipped its own signing key

Published

Lantronix's G520 series cellular gateways trusted software signed with a private key that anyone could download, because the key shipped inside the company's publicly distributed software development kit. That is one of two flaws detailed in a CISA advisory published on September 29, which together could let an attacker run code on the device with root privileges. Researcher Ievgen Bondarenko reported both issues to CISA.

The G520 line connects remote equipment to cellular networks, and CISA lists transportation, energy, and water and wastewater systems as the sectors where it is deployed, worldwide. Firmware 2.6.0.4R6_stable is affected, and Lantronix has fixed both bugs in release 2.6.0.7R6.

A signature check that could not be trusted twice over

The more serious problem, CVE-2026-91191, is about how the gateway decides whether a software package is genuine. CISA describes two separate failures. During boot, a stock routine turns off signature verification in the package manager's configuration before restoring optional packages from a writable, unsigned feed. And the production private key, whose matching public key is trusted by both stable and beta firmware, sits in the public SDK. CISA's point is blunt: even if signature checking is switched back on, the exposed key lets an attacker produce signatures the device will keep accepting. Anyone able to supply a malicious package could get code running as root during installation.

The second flaw, CVE-2026-84409, starts with the update check itself. The gateway fetches update metadata over unencrypted HTTP and stores part of it. The web interface later drops that stored value straight into the page as HTML, so attacker-controlled metadata can execute as script, a class of bug known as cross-site scripting. Because the same authenticated web origin also offers an interface that runs system commands as root, CISA says an attacker who can influence that metadata could execute arbitrary code in the device's administrative context.

Both bugs score 7.5 (High) under CVSS v3.1 and 7.7 under CVSS v4. The scores reflect real preconditions: the vector strings require user interaction and a higher attack complexity, since an attacker needs to be in a position to tamper with update traffic or feed the device a package. CISA says no known public exploitation has been reported to it.

Update to firmware 2.6.0.7R6

Lantronix's fix is release 2.6.0.7R6, available from the vendor's firmware page, with background in its vulnerability library. Beyond patching, CISA recommends keeping control system devices off the internet, behind firewalls and separate from business networks, and using a secured, up-to-date VPN for remote access. The advisory does not say whether the fixed release replaces or revokes the exposed key, so operators should ask Lantronix directly.

Remote gateways like this have drawn attention before, as with the root command injection in Haiwell industrial gateways in August. The lesson here is narrower and harder: a signature check is only as good as the secrecy of the key behind it, and once that key is public, the check is decoration.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions