CVE-2026-11505
Deferred Deferred - Pending Action
Hard-Coded Cryptographic Key in GL.iNet Routers

Publication date: 2026-06-08

Last updated on: 2026-06-08

Assigner: VulDB

Description
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-08
Last Modified
2026-06-08
Generated
2026-06-08
AI Q&A
2026-06-08
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 9 associated CPEs
Vendor Product Version / Range
gl.inet a1300 4.8
gl.inet ax1800 4.8
gl.inet axt1800 4.8
gl.inet mt2500 4.8
gl.inet mt3000 4.8
gl.inet mt6000 4.8
gl.inet x3000 4.8
gl.inet xe3000 4.8
gl.inet glnassys to 4.9.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.
CWE-320 Key Management Errors
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-11505 is a vulnerability in the glnassys component of certain GL.iNet devices where a hard-coded default authentication token is used. This flaw allows attackers to gain unauthorized access to network storage-related interfaces and execute malicious commands remotely. The affected devices include models such as A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, and XE3000 with firmware versions prior to 4.9.x.

Impact Analysis

This vulnerability can allow an attacker to remotely execute unauthorized commands on affected GL.iNet devices by exploiting the hard-coded authentication token. This could lead to unauthorized access to network storage interfaces, potentially compromising sensitive data or device functionality. The attack requires a high level of complexity and is considered difficult to exploit, but successful exploitation could result in security breaches and system instability.

Detection Guidance

This vulnerability involves a hard-coded default authentication token in the glnassys component of GL.iNet devices, which allows unauthorized access to network storage-related interfaces.

Detection can focus on identifying the presence of vulnerable firmware versions (prior to 4.9.x) on affected devices such as MT6000, A1300, AX1800, and others.

Since the vulnerability allows unauthorized command execution via the hard-coded token, network monitoring for unusual or unauthorized access attempts to the glnassys interfaces could help detect exploitation attempts.

Specific commands are not provided in the resources, but general approaches include checking the firmware version on devices and scanning for default authentication tokens or unauthorized access attempts in logs.

Mitigation Strategies

The primary mitigation step is to upgrade the affected GL.iNet devices to firmware version 4.9.0 or later, as this version addresses the vulnerability.

Upgrading the firmware removes the hard-coded default authentication token and prevents unauthorized command execution.

Until the upgrade can be applied, restrict network access to the affected devices, especially limiting remote access to the glnassys component interfaces.

Compliance Impact

CVE-2026-11505 involves a hard-coded default authentication token in the glnassys component of GL.iNet devices, which allows unauthorized access and execution of malicious commands. This unauthorized access risk could potentially lead to exposure or compromise of sensitive data handled by the affected devices.

Such a vulnerability may impact compliance with data protection regulations like GDPR or HIPAA, which require adequate security measures to protect personal and sensitive information from unauthorized access. The presence of a hard-coded cryptographic key and the possibility of remote exploitation could be considered a failure to maintain appropriate security controls.

Upgrading to firmware version 4.9.0 mitigates the issue, and applying this update is advised to restore compliance and reduce security risks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11505. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart