Vulnerability in GL.iNet Routers Affecting Hard-Coded Cryptographic Keys
CVE-2026-11505

2.3LOW

Key Information:

Vendor

Gl.inet

Status
Vendor
CVE Published:
8 June 2026

What is CVE-2026-11505?

A vulnerability has been identified in several GL.iNet router models which relates to the use of hard-coded cryptographic keys within the glnassys component. This flaw allows attackers to execute remote manipulation, potentially compromising the security of the devices. Attackers must navigate a complex process to exploit this vulnerability, which increases the difficulty of successful attacks. Users are advised to upgrade to version 4.9.0 to effectively mitigate the risk associated with this vulnerability.

Affected Version(s)

A1300 4.8.*

AX1800 4.8.*

AXT1800 4.8.*

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GLiNet (VulDB User)
.