A vulnerability was found in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. It has been declared as critical. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-18584. The attack can only be initiated within the local network. No exploit exists.
The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.