Description
The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local network can perform unlimited password attempts against the admin interface.
Published: 2026-01-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 16 Jan 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet ax1800
Gl-inet ax1800 Firmware
CPEs cpe:2.3:h:gl-inet:ax1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.4:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.8:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet ax1800
Gl-inet ax1800 Firmware

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-307
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Thu, 08 Jan 2026 16:30:00 +0000


Thu, 08 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local network can perform unlimited password attempts against the admin interface.
References

Subscriptions

Gl-inet Ax1800 Ax1800 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-08T16:51:52.244Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67090

cve-icon Vulnrichment

Updated: 2026-01-08T16:47:14.119Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T16:15:45.470

Modified: 2026-01-16T21:28:08.207

Link: CVE-2025-67090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses