CVE-2026-91191: CWE-347 in Lantronix G520 Series
The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.
AI Analysis
Technical Summary
The vulnerability in Lantronix G520 Series devices involves the update mechanism's failure to enforce package signature verification consistently. During boot, signature verification is disabled before restoring optional packages from an unsigned feed. Additionally, the publicly distributed SDK exposes the production private key, which corresponds to a public key trusted by stable and beta firmware. This combination allows attackers to craft malicious packages with valid signatures, bypassing authenticity checks and potentially executing arbitrary code with root privileges during package installation.
Potential Impact
An attacker capable of supplying a malicious package can execute arbitrary code with root privileges on affected Lantronix G520 Series devices. This compromises confidentiality, integrity, and availability of the device, potentially leading to full system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, restrict access to the update mechanism and avoid using unsigned or untrusted package feeds.
CVE-2026-91191: CWE-347 in Lantronix G520 Series
Description
The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.
CVSS v3.1
Score 7.5high
Affected software
Lantronix
G520 Series
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Lantronix G520 Series devices involves the update mechanism's failure to enforce package signature verification consistently. During boot, signature verification is disabled before restoring optional packages from an unsigned feed. Additionally, the publicly distributed SDK exposes the production private key, which corresponds to a public key trusted by stable and beta firmware. This combination allows attackers to craft malicious packages with valid signatures, bypassing authenticity checks and potentially executing arbitrary code with root privileges during package installation.
Potential Impact
An attacker capable of supplying a malicious package can execute arbitrary code with root privileges on affected Lantronix G520 Series devices. This compromises confidentiality, integrity, and availability of the device, potentially leading to full system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided in the available data. Until a patch is available, restrict access to the update mechanism and avoid using unsigned or untrusted package feeds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- icscert
- Date Reserved
- 2026-09-17T19:24:31.384Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abc2bf6680226ef684cb661
Added to database: 09/29/2026, 21:21:58 UTC
Last enriched: 09/29/2026, 21:36:11 UTC
Last updated: 09/30/2026, 03:38:31 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.