← Back to CVE List
Vulnerability Intelligence Report
Lantronix G520 Series Cellular Gateway Cross-site Scripting

CVE-2026-84409

The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.

Cross-Site Scripting (XSS) No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:1.7
Impact Score:5.9
EPSS Probability:0.39%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

Affected Products & Versions

Vendor Product Affected Versions
Lantronix G520 Series 2.6.0.4R6 stable (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.391%
Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA
Reserved2026-09-17T19:24:31
Published2026-09-29T21:02:09
Last Updated2026-09-30T15:28:15

LINK COPIED TO CLIPBOARD