CVE-2026-11505
Deferred
Deferred - Pending Action
Hard-Coded Cryptographic Key in GL.iNet Routers
Publication date: 2026-06-08
Last updated on: 2026-06-08
Assigner: VulDB
Description
Description
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key
. The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gl.inet | a1300 | 4.8 |
| gl.inet | ax1800 | 4.8 |
| gl.inet | axt1800 | 4.8 |
| gl.inet | mt2500 | 4.8 |
| gl.inet | mt3000 | 4.8 |
| gl.inet | mt6000 | 4.8 |
| gl.inet | x3000 | 4.8 |
| gl.inet | xe3000 | 4.8 |
| gl.inet | glnassys | to 4.9.0 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |
| CWE-320 | Key Management Errors |