CVE 8.3 HIGH

CVE-2025-44018_CVE-2025-44018

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

Description

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

Basic Information

ID CVE-2025-44018
Source talos
Published Nov 24, 2025 at 15:11

Affected Product

Vendor GL-Inet
Product GL-AXT1800
Version 4.7.0
Affected Versions GL-Inet GL-AXT1800 4.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.