Home
HIGH: 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H 4.7.0
affected
Description
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Problem types
CWE-295: Improper Certificate Validation
Product status
Credits
Discovered by Lilith >_> of Cisco Talos.
References
www.talosintelligence.com/...ability_reports/TALOS-2025-2230
talosintelligence.com/vulnerability_reports/TALOS-2025-2230