CVE-2026-18584

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-03 06:16

Updated : 2026-08-12 21:00


NVD link : CVE-2026-18584

Mitre link : CVE-2026-18584

CVE.ORG link : CVE-2026-18584


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization