AI analysis
Lantronix G520 Series cellular gateways can treat unauthorized software packages as authentic because package signature checks are improperly enforced (CWE-347). During boot, a stock function turns off OPKG signature verification before optional packages are restored from a writable, unsigned feed, and the publicly distributed SDK includes the production private key trusted by both stable and beta firmware. An attacker who can supply a malicious package may therefore get it accepted as valid and execute arbitrary code as root during installation; restoring signature checks does not help while the exposed key remains trusted. Affected devices are G520 Series units running those stable or beta builds; exact version numbers were not published in the provided data. The issue is not on CISA’s KEV list, no public proof-of-concept is known, and CVSS 4.0 rates it 7.7 (high) with network access, some attack preconditions, and passive user interaction.
What to do: Follow Lantronix and CISA ICS advisories for firmware that restores OPKG signature verification and replaces the exposed production signing key; do not treat a verification-only change as sufficient while that key is still trusted. Until a fix is installed, block untrusted or writable package feeds, avoid installing optional packages, and keep the gateways segmented from networks that can supply packages.
Affected
| Lantronix G520 Series Cellular Gateway | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
The device's update mechanism includes conditions that allow unauthorized software packages to be accepted as authentic. During the boot process, the stock done function disables signature verification in the OPKG configuration before restoring optional packages from a writable, unsigned feed. Separately, the publicly distributed SDK contains the production private key whose corresponding public key is trusted by both stable and beta firmware builds. Either issue undermines package authenticity, and together they allow an attacker to provide packages that appear valid to the system. Even if signature enforcement is restored, the exposed production key enables an attacker to generate signatures that the device will continue to trust. An attacker who can supply a malicious package may be able to execute arbitrary code with root privileges during installation.