CVE Vulnerabilities

CVE-2025-44018

Improper Certificate Validation

Published: Nov 24, 2025 | Modified: Nov 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Potential Mitigations

References