The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local network can perform unlimited password attempts against the admin interface.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 16 Jan 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet ax1800
Gl-inet ax1800 Firmware
CPEs cpe:2.3:h:gl-inet:ax1800:-:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.4:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:ax1800_firmware:4.6.8:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet ax1800
Gl-inet ax1800 Firmware

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-307
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}


Thu, 08 Jan 2026 16:30:00 +0000


Thu, 08 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local network can perform unlimited password attempts against the admin interface.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-08T16:51:52.244Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67090

cve-icon Vulnrichment

Updated: 2026-01-08T16:47:14.119Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-08T16:15:45.470

Modified: 2026-01-16T21:28:08.207

Link: CVE-2025-67090

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses