Description
A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
Problem types
Use of Hard-coded Cryptographic Key
Product status
4.9.0
4.9.0
4.9.0
4.9.0
4.9.0
4.9.0
4.9.0
4.9.0
Timeline
| 2026-06-07: | Advisory disclosed |
| 2026-06-07: | VulDB entry created |
| 2026-06-07: | VulDB entry last update |
Credits
GLiNet (VulDB User)
References
vuldb.com/vuln/369125 (VDB-369125 | GL.iNet XE3000 glnassys hard-coded key)
vuldb.com/vuln/369125/cti (VDB-369125 | CTI Indicators (IOB, IOC, TTP))
vuldb.com/cve/CVE-2026-11505 (CVE-2026-11505 | CVE Analysis and Report)
vuldb.com/submit/835698 (Submit #835698 | GL.iNet Router 4.8.x unauthorized)
github.com/...es a risk to unauthorized command execution.md
cloud-static-test.gl-inet.cn/...1800-squashfs-sysupgrade.tar