CVE-2025-44018: Gl-Inet Gl-AXT1800
High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
Affected products
- Gl-Inet Gl-AXT1800: version 4.7.0 only
Published 2025-11-24. Last modified 2026-10-08.