Firmware Downgrade Vulnerability in GL-Inet GL-AXT1800
CVE-2025-44018

8.3HIGH

Key Information:

Vendor

Gl-inet

Vendor
CVE Published:
24 November 2025

What is CVE-2025-44018?

A vulnerability exists in the Over-The-Air (OTA) Update functionality of GL-Inet's GL-AXT1800 router that allows an attacker to exploit a specially crafted .tar file. By executing a man-in-the-middle attack, the attacker can initiate a firmware downgrade process, potentially leading to the installation of older firmware versions that may contain known security flaws. This incident can compromise the security of affected devices, making them susceptible to various attacks.

Affected Version(s)

GL-AXT1800 4.7.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Lilith >_> of Cisco Talos.
.
CVE-2025-44018 : Firmware Downgrade Vulnerability in GL-Inet GL-AXT1800