CVE-2026-11505
MEDIUMCVSS v3.1: 5.0 · EPSS: 0.0004 (13.3 percentile)
Source data as of:
At a glance
- Severity
- MEDIUM
- CVSS
- 5.0 v3.1 · NVD
- EPSS
- 0.0004 (13.3 percentile) · FIRST.org
- CISA KEV
- No
- Attack conditions (CVSS vector)
- NetworkNo user interaction · Source: NVD Vector
- Published
- 2026-06-08 · Modified: 2026-06-08
- References
- Jump to references (6)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Reference https://cloud-static-test.gl-inet.cn/security/openwrt-ipq60xx-glinet_ax1800-squashfs-sysup…
- Reference https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/The%20hard%20coded%20default%20authe…
- Reference https://vuldb.com/cve/CVE-2026-11505
- Reference https://vuldb.com/submit/835698
- Reference https://vuldb.com/vuln/369125
- Reference https://vuldb.com/vuln/369125/cti