Unauthorized Software Package Acceptance in Lantronix Devices
CVE-2026-91191
7.7HIGH
What is CVE-2026-91191?
The update mechanism in Lantronix devices allows unauthorized software packages to be interpreted as authentic. This occurs due to the disabling of signature verification during the boot process, which permits the installation of unsigned packages from writable feeds. Furthermore, the production private key is exposed in the publicly distributed SDK, enabling attackers to generate valid signatures for malicious packages. As a result, an attacker who can exploit these vulnerabilities may execute arbitrary code with root privileges on the affected devices, compromising their security.
Affected Version(s)
G520 Series 2.6.0.4R6 stable
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ievgen Bondarenko reported this vulnerability to CISA.
