CVE-2026-18584

MEDIUM

GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

References (5)

Core 5
Core References
Vdb Entry vdb-entry
VDB-385413 | GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
https://vuldb.com/vuln/385413
Signature, Permissions Required signature permissions-required
VDB-385413 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/385413/cti
Third Party Advisory third-party-advisory
CVE-2026-18584 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18584
Third Party Advisory third-party-advisory
Submit #849283 | GL.iNet Router v4.8.1 unauthorized
https://vuldb.com/submit/849283

Scores

CVSS v3 5.4
EPSS 0.0023
EPSS Percentile 13.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-266 CWE-285
Status published
Products (6)
GL.iNet/E5800 20260707
GL.iNet/E750 20260707
GL.iNet/X2000 20260707
GL.iNet/X3000 20260707
GL.iNet/XE300 20260707
GL.iNet/XE3000 20260707
Published Aug 03, 2026
Tracked Since Aug 03, 2026