📦 Ax1800 Firmware

by Gl Inet

🔍 What is Ax1800 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-39227

CRITICAL CVSS 9.8 Aug 6, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary code or perform directory traversal attacks on affected GL-iNet routers via the /cgi-bin/glc endpoint. Attackers can exploit in...

CVE-2024-39225

CRITICAL CVSS 9.8 Aug 6, 2024

This CVE describes a remote code execution vulnerability in multiple GL-iNet router models that allows attackers to bypass authentication mechanisms and execute arbitrary code. The vulnerability affec...

CVE-2024-39228

CRITICAL CVSS 9.8 Aug 6, 2024

This CVE describes a shell injection vulnerability in GL-iNet router firmware that allows remote attackers to execute arbitrary commands with root privileges. The vulnerability exists in the OpenVPN c...

CVE-2024-45261

HIGH CVSS 8.0 Oct 24, 2024

This vulnerability allows attackers to bypass authentication on affected GL-iNet routers by exploiting improperly generated session IDs (SIDs) that aren't tied to specific users. Attackers can generat...

CVE-2024-45263

HIGH CVSS 8.8 Oct 24, 2024

This vulnerability allows attackers to upload arbitrary files to affected GL-iNet router devices via the upload interface. Once uploaded, these files can be executed, potentially leading to informatio...

CVE-2024-27356

HIGH CVSS 7.5 Feb 27, 2024

This vulnerability allows attackers to download files including logs from affected GL-iNet devices via commands, potentially exposing sensitive user information. It affects multiple GL-iNet router mod...

CVE-2025-67090

MEDIUM CVSS 5.1 Jan 8, 2026

The LuCI web interface on GL.Inet AX1800 routers lacks rate limiting or account lockout mechanisms on the authentication endpoint, allowing unauthenticated attackers on the local network to perform un...

CVE-2025-67091

MEDIUM CVSS 6.5 Jan 8, 2026

A race condition vulnerability in GL.iNet AX1800 router firmware allows authenticated attackers to bypass file locking mechanisms and potentially execute arbitrary code with root privileges. The issue...

CVE-2024-45259

MEDIUM CVSS 6.5 Oct 24, 2024

This vulnerability allows attackers to delete arbitrary files on affected GL-iNet router devices by intercepting HTTP requests and manipulating the filename parameter in the download interface. Attack...