PT-2026-67143 · Gl.Inet · Xe3000+5
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
GL.iNet E5800 versions prior to 20260707
GL.iNet E750 versions prior to 20260707
GL.iNet X2000 versions prior to 20260707
GL.iNet X3000 versions prior to 20260707
GL.iNet XE3000 versions prior to 20260707
GL.iNet XE300 versions prior to 20260707
Description
A flaw in the eSIM LPA API component allows for improper authorization. This issue occurs within the
/sdk/v1 file and can be exploited by an attacker located within the local network.Recommendations
Update GL.iNet E5800 to a version released after 20260707.
Update GL.iNet E750 to a version released after 20260707.
Update GL.iNet X2000 to a version released after 20260707.
Update GL.iNet X3000 to a version released after 20260707.
Update GL.iNet XE3000 to a version released after 20260707.
Update GL.iNet XE300 to a version released after 20260707.
Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
E5800
E750
X2000
X3000
Xe300
Xe3000