Authentication Bypass Vulnerability in GL.Inet AX1800 by GL.iNet
CVE-2025-67090

5.1MEDIUM

Key Information:

Vendor

GL.iNet

Vendor
CVE Published:
8 January 2026

What is CVE-2025-67090?

The LuCI web interface on GL.Inet AX1800 versions 4.6.4 and 4.6.8 exhibits a critical vulnerability due to the absence of rate limiting and account lockout mechanisms on the authentication endpoint (/cgi-bin/luci). This flaw enables an unauthenticated attacker within the local network to execute unlimited password guessing attempts against the admin interface, potentially compromising device security. To mitigate this risk, users are advised to update to version 4.8.2 or later, where the vulnerability has been addressed.

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.