CVE-2025-44018: Gl-Inet Gl-AXT1800

High severity, CVSS 8.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

Affected products

  • Gl-Inet Gl-AXT1800: version 4.7.0 only

Published 2025-11-24. Last modified 2026-10-08.