Lantronix's G520 cellular gateway ships two bugs that together let an attacker plant root-level malware disguised as an official firmware update.
CISA disclosed two high severity flaws in the G520 Series Cellular Gateway, hardware used to connect industrial equipment to cellular networks. The first is a cross-site scripting bug: the device fetches update metadata over plain HTTP, stores it, then prints it straight into the web interface's HTML, letting attacker-controlled text run as script inside the admin panel. The second is worse. The gateway's boot process disables OPKG signature checks before pulling packages from an unsigned feed, and the SDK that Lantronix distributes publicly contains the very private key used to sign production firmware. Both flaws affect firmware 2.6.0.4R6_stable and are fixed in 2.6.0.7R6.
Chain the two together and an attacker with a foothold in the admin interface can push a fake update the device treats as authentic, then run it with root privileges. These gateways sit in transportation, energy, and water utility networks worldwide, the kind of infrastructure where an unpatched device tends to stay unpatched. CISA says it has no evidence of active exploitation yet, but the fix still depends on someone finding and flashing 2.6.0.7R6 on gear that's often installed once and forgotten.
A private signing key loose in a public SDK is a familiar way for IoT vendors to undercut their own security story - the lock only works if nobody photocopies the key.