AI analysis
Lantronix G520 Series cellular gateways retrieve software-update metadata over unencrypted HTTP and store part of that metadata for later use. A management interface returns the stored value in JSON, and the update web page inserts it directly as HTML, so attacker-controlled metadata can run as script (CWE-79). The same authenticated origin also exposes an interface that can run system commands as root, so script in the administrative context can lead to arbitrary code execution on the device. An attacker must be able to influence the HTTP update metadata and a user must interact with the update UI (CVSS 4.0 7.7, attack requirements present, user interaction required). The issue is not in CISA KEV and no public proof-of-concept is known.
What to do: Apply the Lantronix firmware update referenced in the ICS-CERT advisory as soon as it is available, and until then keep the G520 management interface off untrusted networks. Prefer a path where update metadata cannot be modified in transit, and confirm the web UI is not reachable from the internet.
Affected
| Lantronix G520 Series Cellular Gateway | — |
Estimated exposure
nicheNo basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The device's update mechanism retrieves metadata for software updates over an unencrypted HTTP connection and stores portions of that metadata for later use. A management interface subsequently returns this stored value in a JSON response, and the web interface responsible for displaying update information inserts that value directly into the page as HTML. This behavior allows attacker‑controlled metadata to be interpreted as script content. In addition, the same authenticated origin provides an interface capable of executing system‑level commands with root privileges. An attacker able to influence update metadata could exploit these conditions to execute arbitrary code within the administrative context of the device.