CVE-2025-44018

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Configurations

No configuration.

History

24 Nov 2025, 17:16

Type Values Removed Values Added
References
  • () https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2230 -

24 Nov 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-24 16:15

Updated : 2025-11-25 22:16


NVD link : CVE-2025-44018

Mitre link : CVE-2025-44018

CVE.ORG link : CVE-2025-44018


JSON object : View

Products Affected

No product.

CWE
CWE-295

Improper Certificate Validation