CVE-2026-18584: Gl.inet e5800
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected products
- Gl.inet e5800: version 20260707 only
- Gl.inet e750: version 20260707 only
- Gl.inet x2000: version 20260707 only
- Gl.inet x3000: version 20260707 only
- Gl.inet XE300: version 20260707 only
- Gl.inet XE3000: version 20260707 only
Published 2026-08-03. Last modified 2026-08-12.