CVE-2026-18584: GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18584?
The severity of CVE-2026-18584 is rated as medium with a score of 5.4.
What products are affected by CVE-2026-18584?
CVE-2026-18584 affects GL.iNet models E5800, E750, X2000, X3000, XE3000, and XE3000 using eSIM LPA API v1.
How do I fix CVE-2026-18584?
To fix CVE-2026-18584, update the eSIM LPA API to a version released after 20260707.
What type of vulnerability is CVE-2026-18584?
CVE-2026-18584 is characterized as an improper authorization vulnerability in the eSIM LPA API.
Can CVE-2026-18584 be exploited remotely?
No, CVE-2026-18584 can only be exploited from within the local network.