A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
History

Mon, 08 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet a1300
Gl-inet ax1800
Gl-inet axt1800
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt6000
Gl-inet x3000
Gl-inet xe3000
Vendors & Products Gl-inet
Gl-inet a1300
Gl-inet ax1800
Gl-inet axt1800
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt6000
Gl-inet x3000
Gl-inet xe3000

Mon, 08 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised.
Title GL.iNet XE3000 glnassys hard-coded key
First Time appeared Gl.inet
Gl.inet a1300
Gl.inet ax1800
Gl.inet axt1800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt6000
Gl.inet x3000
Gl.inet xe3000
Weaknesses CWE-320
CWE-321
CPEs cpe:2.3:a:gl.inet:a1300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:ax1800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:axt1800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
Vendors & Products Gl.inet
Gl.inet a1300
Gl.inet ax1800
Gl.inet axt1800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt6000
Gl.inet x3000
Gl.inet xe3000
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:N/AC:H/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-06-08T10:15:09.229Z

Updated: 2026-06-08T10:15:09.229Z

Reserved: 2026-06-07T14:06:05.114Z

Link: CVE-2026-11505

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-08T12:16:30.747

Modified: 2026-06-08T12:16:30.747

Link: CVE-2026-11505

cve-icon Redhat

No data.