PT-2025-47925 · Gl.Inet · Gl-Ax1800

Lilith >_>

·

Published

2025-11-24

·

Updated

2025-11-24

·

CVE-2025-44018

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GL-Inet GL-AXT1800 version 4.7.0
Description A flaw exists in the Over-The-Air (OTA) Update functionality that allows for a firmware downgrade. An attacker can use a specially crafted .tar file to trigger this issue. A man-in-the-middle attack can be used to exploit this flaw.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-44018

Affected Products

Gl-Ax1800