PT-2026-67143 · Gl.Inet · Xe3000+5

·

CVE-2026-18584

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions GL.iNet E5800 versions prior to 20260707 GL.iNet E750 versions prior to 20260707 GL.iNet X2000 versions prior to 20260707 GL.iNet X3000 versions prior to 20260707 GL.iNet XE3000 versions prior to 20260707 GL.iNet XE300 versions prior to 20260707
Description A flaw in the eSIM LPA API component allows for improper authorization. This issue occurs within the /sdk/v1 file and can be exploited by an attacker located within the local network.
Recommendations Update GL.iNet E5800 to a version released after 20260707. Update GL.iNet E750 to a version released after 20260707. Update GL.iNet X2000 to a version released after 20260707. Update GL.iNet X3000 to a version released after 20260707. Update GL.iNet XE3000 to a version released after 20260707. Update GL.iNet XE300 to a version released after 20260707.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18584

Affected Products

E5800
E750
X2000
X3000
Xe300
Xe3000