CVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-04 08:16

Updated : 2026-09-09 15:41


NVD link : CVE-2026-18754

Mitre link : CVE-2026-18754

CVE.ORG link : CVE-2026-18754


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key