Improper Authorization in GL.iNet Devices Affects eSIM LPA API Functionality
CVE-2026-18584

5.3MEDIUM

Key Information:

Vendor

Gl.inet

Status
E5800
E750
X2000
X3000
Vendor
CVE Published:
3 August 2026

What is CVE-2026-18584?

A security vulnerability has been identified in various GL.iNet router models impacting their eSIM LPA API. An unknown function within the file /sdk/v1 allows for improper authorization, enabling potential attackers to exploit this flaw. This manipulation is restricted to initiation within the local network environment. The vulnerability was disclosed to the vendor prior to public knowledge, who has verified its existence and acknowledged its implications.

Affected Version(s)

E5800 20260707

E750 20260707

X2000 20260707

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GLiNet (VulDB User)
VulDB CNA Team
.