Unauthorized Software Package Acceptance in Lantronix Devices
CVE-2026-91191

7.7HIGH

Key Information:

Vendor

Lantronix

Vendor
CVE Published:
29 September 2026

What is CVE-2026-91191?

The update mechanism in Lantronix devices allows unauthorized software packages to be interpreted as authentic. This occurs due to the disabling of signature verification during the boot process, which permits the installation of unsigned packages from writable feeds. Furthermore, the production private key is exposed in the publicly distributed SDK, enabling attackers to generate valid signatures for malicious packages. As a result, an attacker who can exploit these vulnerabilities may execute arbitrary code with root privileges on the affected devices, compromising their security.

Affected Version(s)

G520 Series 2.6.0.4R6 stable

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ievgen Bondarenko reported this vulnerability to CISA.
.