CVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-04 08:16

Updated : 2026-09-09 15:41


NVD link : CVE-2026-18753

Mitre link : CVE-2026-18753

CVE.ORG link : CVE-2026-18753


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key