CVE-2025-44018: High severity gl-inet GL-AXT1800 vulnerability
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44018?
CVE-2025-44018 is considered a high severity vulnerability due to its potential for exploitation through a man-in-the-middle attack.
How do I fix CVE-2025-44018?
To fix CVE-2025-44018, update the GL-Inet GL-AXT1800 firmware to the latest version that addresses the vulnerability.
What can an attacker achieve with CVE-2025-44018?
An attacker can exploit CVE-2025-44018 to downgrade the firmware of the GL-Inet GL-AXT1800 device, potentially compromising its security.
Is there a workaround for CVE-2025-44018?
Currently, the best workaround for CVE-2025-44018 is to disable OTA updates until the firmware is updated.
Which devices are affected by CVE-2025-44018?
CVE-2025-44018 affects the GL-Inet GL-AXT1800 running firmware version 4.7.0.