๐Ÿ” CVE Alert

CVE-2026-18584

MEDIUM 5.4

GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CWE CWE-285 CWE-266
Vendor gl.inet
Product e5800
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for gl.inet e5800

Be the first to know when new medium vulnerabilities affecting gl.inet e5800 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GL.iNet / E5800
20260707
GL.iNet / E750
20260707
GL.iNet / X2000
20260707
GL.iNet / X3000
20260707
GL.iNet / XE3000
20260707
GL.iNet / XE300
20260707

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/385413 vuldb.com: https://vuldb.com/vuln/385413/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18584 vuldb.com: https://vuldb.com/submit/849283 github.com: https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Unauthenticated%20access%20to%20eSIM%20LPA%20API%20via%20nginx%20proxy%20bypass.md

Credits

๐Ÿ” GLiNet (VulDB User) VulDB CNA Team