216.73.216.133

CVE-2025-44018

· Published 24/11/2025 16:15 · Modified 25/11/2025 22:16

Labels: CVE-2025-44018 2025-11-24CVE-2025-44018CWE-295[email protected]

Essential information

Published
24/11/2025 16:15
Modified
25/11/2025 22:16
Author
Creator
CVSS
8.3 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References