Description
An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.
Published: 2026-01-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 16 Jan 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet ax1800 Firmware
CPEs cpe:2.3:h:gl-inet:ax1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.4:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.8:*:*:*:*:*:*:*
Vendors & Products Gl-inet ax1800 Firmware

Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet ax1800
Vendors & Products Gl-inet
Gl-inet ax1800

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-377 CWE-307

Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-377
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Thu, 08 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.
References

Subscriptions

Gl-inet Ax1800 Ax1800 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-08T16:10:44.603Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67091

cve-icon Vulnrichment

Updated: 2026-01-08T16:03:24.452Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T16:15:45.577

Modified: 2026-01-16T21:28:39.047

Link: CVE-2025-67091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-09T13:24:55Z

Weaknesses