Unencrypted HTTP Update Mechanism in Lantronix G520 Series Devices
CVE-2026-84409

7.7HIGH

Key Information:

Vendor

Lantronix

Vendor
CVE Published:
29 September 2026

What is CVE-2026-84409?

The G520 Series devices from Lantronix exhibit a vulnerability in their update process whereby metadata for software updates is fetched over an unencrypted HTTP connection. This metadata is stored for later usage and can be retrieved via a management interface, which incorporates this information directly into the web page as HTML. Such a design flaw allows attacker-controlled metadata to be executed as script content. Additionally, the same authenticated origin includes an interface that can execute system-level commands with root privileges. An attacker with the ability to manipulate this update metadata could potentially execute arbitrary code within the context of the device's administrative interface.

Affected Version(s)

G520 Series 2.6.0.4R6 stable

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ievgen Bondarenko reported this vulnerability to CISA.
.