CVE-2026-11505
Description
GL.iNet devices running firmware 4.8.x are vulnerable to hard-coded cryptographic key usage, allowing remote command execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
GL.iNet devices running firmware 4.8.x are vulnerable to hard-coded cryptographic key usage, allowing remote command execution.
Vulnerability
A flaw exists in the glnassys component of GL.iNet devices including A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, and XE3000 running firmware version 4.8.x. This vulnerability involves the use of a hard-coded default authentication token, which can be exploited to call network storage related interfaces [1].
Exploitation
An attacker can remotely exploit this vulnerability by leveraging the hard-coded default token. This token allows unauthorized access to network storage related interfaces, enabling malicious attacks such as command execution. The attack requires a high level of complexity and is considered difficult to exploit [1].
Impact
Successful exploitation allows an attacker to use the default tokens to call any network storage related interface. This can lead to unauthorized access and command execution on the affected devices, compromising the system's integrity and confidentiality [1].
Mitigation
GL.iNet has released firmware version 4.9.x, which mitigates this issue for all affected products, including MT6000, A1300, AX1800, AXT1800, MT2500, MT3000, X3000, and XE3000. Upgrading to version 4.9.0 or later is advised [1].
AI Insight generated on Jun 8, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- cloud-static-test.gl-inet.cn/security/openwrt-ipq60xx-glinet_ax1800-squashfs-sysupgrade.tarnvd
- github.com/gl-inet/CVE-issues/blob/main/4.0.0/The%20hard%20coded%20default%20authentication%20token%20in%20gl%20nas%20sys%20poses%20a%20risk%20to%20unauthorized%20command%20execution.mdnvd
- vuldb.com/cve/CVE-2026-11505nvd
- vuldb.com/submit/835698nvd
- vuldb.com/vuln/369125nvd
- vuldb.com/vuln/369125/ctinvd
News mentions
0No linked articles in our index yet.