CVE 7.5 HIGH

GL.iNet GL-RM1/GL-RM10/GL-RM10RC/GL-RM1PE Factory Reset improper authentication_CVE-2026-5959

7.5 / 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X

Description

A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory Reset Handler. Performing a manipulation results in improper authentication. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 1.8.2 can resolve this issue. It is advisable to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Basic Information

ID CVE-2026-5959
Source VulDB
Published Apr 9, 2026 at 14:30

Affected Product

Vendor GL.iNet
Product GL-RM1
Version 1.8.1
Affected Versions GL.iNet GL-RM1 1.8.1
GL.iNet GL-RM10 1.8.1
GL.iNet GL-RM10RC 1.8.1
GL.iNet GL-RM1PE 1.8.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.