Static RSA Private Key Vulnerability in Lighttpd Web Server by GeoVision
CVE-2026-18753
9.1CRITICAL
What is CVE-2026-18753?
The Lighttpd web server firmware by GeoVision contains a static RSA private key used for TLS termination, which is embedded within the software. This exposure compromises both the confidentiality and integrity of HTTPS communications. Malicious actors could exploit this vulnerability to decrypt secure traffic and potentially spoof servers, leading to unauthorized access and data breaches.
Affected Version(s)
GV-AS1620 (AS-Manager) Linux V2.07
GV-AS1620 (AS-Manager) Linux V2.08
