CVE-2025-44018
8.3GL-Inet · GL-AXT1800
A firmware downgrade vulnerability in the GL-Inet GL-AXT1800 OTA update mechanism allows an attacker to force a downgrade via a crafted .tar file using a man-in-the-middle attack.
Executive summary
The GL-Inet GL-AXT1800 is vulnerable to a firmware downgrade attack that could allow a remote adversary to compromise device integrity via a man-in-the-middle vector.
Vulnerability
This vulnerability, classified as improper certificate validation (CWE-295), exists within the OTA update functionality. An unauthenticated attacker can perform a man-in-the-middle attack to inject a malicious .tar file, facilitating a firmware downgrade.
Business impact
Successful exploitation of this flaw allows an attacker to downgrade the device firmware to a version with known, exploitable vulnerabilities, effectively bypassing existing security protections. Given the high CVSS score of 8.3, this risk is significant, as it could lead to full system compromise, persistent unauthorized access, and potential exfiltration of sensitive network traffic routed through the device.
Remediation
Immediate Action: Contact GL-Inet support or monitor official vendor channels for the release of a patched firmware version that addresses the improper certificate validation in the OTA process.
Proactive Monitoring: Monitor network traffic for suspicious man-in-the-middle activity or unauthorized attempts to initiate firmware update processes.
Compensating Controls: Ensure the device is managed within a segmented network and avoid performing firmware updates over untrusted or public network connections.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability necessitates immediate vigilance, as it effectively nullifies the security benefits of previously installed updates. Administrators should prioritize verifying the authenticity of firmware updates and apply the vendor-provided patch as soon as it becomes available to restore the integrity of the update mechanism.
More GL-Inet CVEs
Sources
Originally found and disclosed by Discovered by Lilith >, _>, of Cisco Talos., per the CVE Program record.