CVE-2026-18584
GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
| CWE | CWE-285 CWE-266 |
| Vendor | gl.inet |
| Product | e5800 |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for gl.inet e5800
Be the first to know when new medium vulnerabilities affecting gl.inet e5800 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
GL.iNet / E5800
20260707
GL.iNet / E750
20260707
GL.iNet / X2000
20260707
GL.iNet / X3000
20260707
GL.iNet / XE3000
20260707
GL.iNet / XE300
20260707
References
vuldb.com: https://vuldb.com/vuln/385413 vuldb.com: https://vuldb.com/vuln/385413/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18584 vuldb.com: https://vuldb.com/submit/849283 github.com: https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthenticated%20access%20to%20eSIM%20LPA%20API%20via%20nginx%20proxy%20bypass.md
Credits
๐ GLiNet (VulDB User) VulDB CNA Team