How do I tell whether my Lantronix G520 Series Cellular Gateway is running 2.6.0.4R6_stable?

CISA’s September 29, 2026 advisory lists one affected product version for the Lantronix G520 Series Cellular Gateway: 2.6.0.4R6_stable.
What to compare
Look for the installed software or firmware version on your Lantronix G520 Series Cellular Gateway, then compare it exactly with this value:
`2.6.0.4R6_stable`
If the device shows that version, it matches the affected version named in the advisory.
What is not confirmed here
The provided context does not include the device menu path, command, or management-screen location for checking the version. Use Lantronix product documentation or the device’s management interface to find the installed version.
The important point is the exact version string. Do not treat a different version as affected based only on this post unless CISA or Lantronix says so.
Why the version check matters
CISA associates the Lantronix G520 Series Cellular Gateway advisory with CVE-2026-84409 and CVE-2026-91191. It says successful exploitation could allow software replacement and arbitrary code execution with root privileges.
For current details, check the official advisory before making a final security decision.
What should I do if my Lantronix G520 Series Cellular Gateway is affected by CVE-2026-84409 or CVE-2026-91191?

If your Lantronix G520 Series Cellular Gateway is running the affected version listed by CISA, treat the advisory as a priority item for review.
What CISA confirms
The affected product version in the provided context is:
`G520 Series 2.6.0.4R6_stable`
CISA associates the advisory with CVE-2026-84409 and CVE-2026-91191. The listed weaknesses include cross-site scripting and improper verification of a cryptographic signature.
What the impact could be
CISA says successful exploitation could let an attacker replace software and run arbitrary code with root privileges.
That is the main practical reason to verify whether your device matches the affected version.
What to do next
The provided context does not include a vendor patch version, workaround, or configuration change. So the grounded next step is to read the official CISA advisory and follow any current vendor or CISA instructions there.
Because vulnerability guidance can change quickly, use the source page rather than relying only on a summary.
What changed in CISA’s September 29, 2026 advisory for the Lantronix G520 Series Cellular Gateway?

CISA issued an ICS advisory for the Lantronix G520 Series Cellular Gateway on September 29, 2026.
The main advisory details
The advisory names `G520 Series 2.6.0.4R6_stable` as the affected product version.
It also associates the device with two CVEs:
- CVE-2026-84409
- CVE-2026-91191
The listed weaknesses
The provided context says CISA listed these weakness types:
- Cross-site scripting
- Improper verification of a cryptographic signature
The possible impact
CISA says successful exploitation could allow an attacker to replace software and run arbitrary code with root privileges.
The provided context does not include a confirmed fix version or workaround. Review the current CISA advisory for any later updates before taking action.
Sources / Learn more
Related reading
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- How do I check whether my Siemens Industrial Edge Management deployment is in one of the affected version ranges?; What should administrators do after CISA advisory ICSA-26-265-06 for CVE-2026-18963?; What changed in the Siemens update for the reset-credentials vulnerability?; What is the timeline for the Siemens Industrial Edge Management CISA advisory and fix?
- Should you watch Netflix’s Dark before HBO’s It: Welcome to Derry season 2?
- What should NetScaler ADC and Gateway administrators do first after CISA added CVE-2026-88771 and CVE-2026-88772 to the KEV Catalog?; Which Citrix products are affected by CVE-2026-88771 and CVE-2026-88772?; How are CVE-2026-88771 and CVE-2026-88772 different?; When did CISA add the two Citrix NetScaler vulnerabilities to the Known Exploited Vulnerabilities Catalog?

Leave a Reply