VYPR
Medium severity5.0NVD Advisory· Published Jun 8, 2026· Updated Jun 8, 2026

CVE-2026-11505

CVE-2026-11505

Description

GL.iNet devices running firmware 4.8.x are vulnerable to hard-coded cryptographic key usage, allowing remote command execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

GL.iNet devices running firmware 4.8.x are vulnerable to hard-coded cryptographic key usage, allowing remote command execution.

Vulnerability

A flaw exists in the glnassys component of GL.iNet devices including A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, and XE3000 running firmware version 4.8.x. This vulnerability involves the use of a hard-coded default authentication token, which can be exploited to call network storage related interfaces [1].

Exploitation

An attacker can remotely exploit this vulnerability by leveraging the hard-coded default token. This token allows unauthorized access to network storage related interfaces, enabling malicious attacks such as command execution. The attack requires a high level of complexity and is considered difficult to exploit [1].

Impact

Successful exploitation allows an attacker to use the default tokens to call any network storage related interface. This can lead to unauthorized access and command execution on the affected devices, compromising the system's integrity and confidentiality [1].

Mitigation

GL.iNet has released firmware version 4.9.x, which mitigates this issue for all affected products, including MT6000, A1300, AX1800, AXT1800, MT2500, MT3000, X3000, and XE3000. Upgrading to version 4.9.0 or later is advised [1].

AI Insight generated on Jun 8, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.