Unencrypted HTTP Update Mechanism in Lantronix G520 Series Devices
CVE-2026-84409
What is CVE-2026-84409?
The G520 Series devices from Lantronix exhibit a vulnerability in their update process whereby metadata for software updates is fetched over an unencrypted HTTP connection. This metadata is stored for later usage and can be retrieved via a management interface, which incorporates this information directly into the web page as HTML. Such a design flaw allows attacker-controlled metadata to be executed as script content. Additionally, the same authenticated origin includes an interface that can execute system-level commands with root privileges. An attacker with the ability to manipulate this update metadata could potentially execute arbitrary code within the context of the device's administrative interface.
Affected Version(s)
G520 Series 2.6.0.4R6 stable
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
