A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | |
| Title | GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization | |
| First Time appeared |
Gl.inet
Gl.inet e5800 Gl.inet e750 Gl.inet x2000 Gl.inet x3000 Gl.inet xe300 Gl.inet xe3000 |
|
| Weaknesses | CWE-266 CWE-285 |
|
| CPEs | cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:e750:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x2000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:xe300:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gl.inet
Gl.inet e5800 Gl.inet e750 Gl.inet x2000 Gl.inet x3000 Gl.inet xe300 Gl.inet xe3000 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-03T04:45:07.095Z
Reserved: 2026-08-02T19:23:56.933Z
Link: CVE-2026-18584
No data.
No data.
No data.
OpenCVE Enrichment
No data.