CVE-2026-18584
Received Received - Intake

Improper Authorization in GL.iNet Router Firmware

Vulnerability report for CVE-2026-18584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: VulDB

Description

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
gl.inet e5800 *
gl.inet e750 *
gl.inet x2000 *
gl.inet x3000 *
gl.inet xe3000 *
gl.inet xe300 to 20260707 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects several GL.iNet devices including E5800, E750, X2000, X3000, XE3000 and XE300. It involves improper authorization in the eSIM LPA API component, specifically in the file /sdk/v1. The attack requires access to the local network.

Detection Guidance

Detection requires checking for unauthorized access attempts to the eSIM LPA API at /sdk/v1 on affected GL.iNet devices. Monitor network traffic for local network-based requests targeting this path. Verify if any unauthorized authorization bypasses occur in logs.

Impact Analysis

An attacker within the local network could exploit this to gain unauthorized access or perform actions they shouldn't be able to. This could lead to data exposure or device misuse depending on the device's function.

Compliance Impact

The vulnerability involves improper authorization in GL.iNet devices, allowing local network attacks. This could potentially lead to unauthorized access or data exposure, which may impact compliance with standards requiring strict access controls like GDPR or HIPAA. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Isolate affected devices from the local network if possible. Disable or restrict access to the eSIM LPA API at /sdk/v1. Apply vendor patches or updates if available. Monitor for unusual activity and unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart