A CISA cybersecurity notice published on September 29, 2026 covers flaws in the Lantronix G520 Series cellular gateway. It identifies version 2.6.0.4R6_stable as affected, gives a CVSS 3.1 score of 7.5 (High), and says version 2.6.0.7R6 fixes the issues.
The notice describes two vulnerabilities: improper input handling that can lead to cross-site scripting, and inadequate cryptographic signature verification. In the first case, update metadata may be inserted as HTML in the web interface; the notice connects this condition to an authenticated interface that can run commands with root privileges. The reported potential impact includes replacing software and executing arbitrary code.
If your organization uses this model, identify the devices and confirm their installed versions. Consult the original CISA advisory and Lantronix security and firmware documentation to verify the details and obtain the update. Plan installation through your organization’s change-management process, then confirm that each device is running the fixed version.
When using AI tools to study or apply the advisory, share only the material needed and remove credentials, personal data, and internal network details. Check recommendations, versions, and scores against official publications: the feed translation may not include all technical context.