CVE-2026-18753: Hardcoded Cryptographic Key on GV-AS1620 Controller Firmware (GV-ASManager)
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18753?
The severity of CVE-2026-18753 is critical with a score of 9.1.
How do I fix CVE-2026-18753?
To fix CVE-2026-18753, update the GV-AS1620 Controller Firmware to a version that removes the hardcoded RSA private key.
What risks are associated with CVE-2026-18753?
The risks associated with CVE-2026-18753 include potential breach of confidentiality, integrity of HTTPS communications, and server spoofing.
Who is affected by CVE-2026-18753?
Users and administrators of the GV-AS1620 Controller Firmware are affected by CVE-2026-18753.
What is the nature of the vulnerability in CVE-2026-18753?
The nature of the vulnerability in CVE-2026-18753 is the presence of a hardcoded, static RSA private key in the firmware, leading to security risks.