CVE-2025-44018
BaseFortify
Publication date: 2025-11-24
Last updated on: 2025-11-24
Assigner: Talos
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gl-inet | gl-axt1800 | 4.7.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-295 | The product does not validate, or incorrectly validates, a certificate. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a firmware downgrade issue in the OTA Update functionality of the GL-Inet GL-AXT1800 device running version 4.7.0. An attacker can use a specially crafted .tar file to force the device to downgrade its firmware. This can be exploited through a man-in-the-middle attack.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to downgrade the device firmware to an older, potentially less secure version. This can lead to compromise of confidentiality, integrity, and availability of the device, as indicated by the high CVSS score and impact metrics.