Project and affected component
Software-update metadata handling, the management web interface, and package-authenticity controls.
Security boundary
Externally supplied update information and software packages must remain untrusted until they have passed the controls required for administrative display or privileged installation.
Vulnerability class
CVE-2026-84409: CWE-79, cross-site scripting. CVE-2026-91191: CWE-347, improper verification of cryptographic signatures. CISA assigns each vulnerability a CVSS 3.1 score of 7.5, High.
CVE-2026-84409
Update metadata retrieved over HTTP could reach the management interface without safe handling. CISA describes how attacker-influenced metadata could execute within the administrative context under the documented conditions.
CVE-2026-91191
Weaknesses in package-signature enforcement and signing-key protection undermined package authenticity. CISA describes the potential for attacker-supplied packages to execute code with root privileges during installation.
Root cause
The advisory records two separate trust failures: unsafe handling of update metadata in the administrative interface and ineffective package-authenticity enforcement. The two CVEs do not depend on a mandatory exploit chain.
Public evidence
The public CISA advisory documents both vulnerabilities, identifies firmware 2.6.0.4R6_stable as affected, credits Ievgen Bondarenko, and records remediation in firmware 2.6.0.7R6. This page does not claim an independent patch retest.
Practical impact
Under the conditions documented by CISA, the vulnerabilities could permit arbitrary code execution, including root-level execution through package installation. Exploitation depends on the relevant update-metadata or package-supply conditions.
Disclosure status
Coordinated through CISA. Public advisory ICSA-26-272-01 was published on September 29, 2026, with researcher credit to Ievgen Bondarenko.
Remediation
CISA reports that Lantronix addressed the issues in firmware 2.6.0.7R6. The advisory identifies 2.6.0.4R6_stable as affected.
Sector context
CISA lists Transportation Systems, Energy, and Water and Wastewater Systems as the product's critical-infrastructure sector context. This describes the product's deployment context, not research performed on operational infrastructure.