Authentication Bypass Vulnerability in GL.Inet AX1800 by GL.iNet
CVE-2025-67090
5.1MEDIUM
What is CVE-2025-67090?
The LuCI web interface on GL.Inet AX1800 versions 4.6.4 and 4.6.8 exhibits a critical vulnerability due to the absence of rate limiting and account lockout mechanisms on the authentication endpoint (/cgi-bin/luci). This flaw enables an unauthenticated attacker within the local network to execute unlimited password guessing attempts against the admin interface, potentially compromising device security. To mitigate this risk, users are advised to update to version 4.8.2 or later, where the vulnerability has been addressed.
