Description
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in an unknown function of the /sdk/v1 endpoint of the GL.iNet eSIM LPA API. By manipulating requests to this endpoint, a local attacker can bypass the API’s authorization checks and issue commands that are normally restricted to authenticated or privileged users. This flaw allows unauthorized actions such as modifying device settings, provisioning or deprovisioning eSIM profiles, or otherwise gaining privileged control over the device. The weakness is identified as improper authorization (CWE‑285).

Affected Systems

All GL.iNet routers carrying the E5800, E750, X2000, X3000, XE3000 and XE300 models are impacted up to firmware release 20260707. Those devices rely on the eSIM LPA API endpoint for remote provisioning tasks, and the flaw affects every instance that has not been patched beyond that release date.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity level for this vulnerability. No EPSS score is available, and the flaw is not listed in the CISA KEV catalogue, implying no publicly documented exploitation yet. Because the attack requires local network access, only hosts that can reach the router’s internal interface can potentially exploit the flaw, which limits the threat to environments where the device is connected to an untrusted or poorly segmented local network.

Generated by OpenCVE AI on August 3, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router’s firmware to the latest version that disables the insecure eSIM LPA API authorization callback.
  • Configure network segmentation or firewall rules to block internal hosts that do not require access to the router’s API from reaching the /sdk/v1 endpoint.
  • If a firmware upgrade is not immediately possible, block or disable the /sdk/v1 endpoint on the device to eliminate the vulnerable function.
  • Continuously monitor router logs for unexpected API usage that may indicate an attempted bypass.

Generated by OpenCVE AI on August 3, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet e5800
Gl-inet e750
Gl-inet x2000
Gl-inet x3000
Gl-inet xe300
Gl-inet xe3000
Vendors & Products Gl-inet
Gl-inet e5800
Gl-inet e750
Gl-inet x2000
Gl-inet x3000
Gl-inet xe300
Gl-inet xe3000

Mon, 03 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization
First Time appeared Gl.inet
Gl.inet e5800
Gl.inet e750
Gl.inet x2000
Gl.inet x3000
Gl.inet xe300
Gl.inet xe3000
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:e750:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x2000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:xe300:*:*:*:*:*:*:*:*
Vendors & Products Gl.inet
Gl.inet e5800
Gl.inet e750
Gl.inet x2000
Gl.inet x3000
Gl.inet xe300
Gl.inet xe3000
References
Metrics cvssV2_0

{'score': 4.8, 'vector': 'AV:A/AC:L/Au:N/C:N/I:P/A:P/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T15:37:18.296Z

Reserved: 2026-08-02T19:23:56.933Z

Link: CVE-2026-18584

cve-icon Vulnrichment

Updated: 2026-08-03T13:47:50.819Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T06:16:37.450

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18584

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:51:55Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization