CVE-2026-18753
Last modified
CVE-2026-18753 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| GeoVision Inc. | GV-AS1620 (AS-Manager) | V2.07 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18753?
How severe is CVE-2026-18753?
How do I fix CVE-2026-18753?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18745Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-18749The type=track branch authorises on _is_my_case(t_attach.cas…9.8
- CVE-2026-1875Improper Resource Shutdown or Release vulnerability in Mitsu…7.5
- CVE-2026-18750vinny/views.py: (ModifyEmailNotifications) IDOR: view fetche…5.3
- CVE-2026-18751External control of file name or path vulnerability in Citri…5.2
- CVE-2026-18752The Persistent Login plugin for WordPress is vulnerable to g…6.5
- CVE-2026-18754The product firmware contains an embedded, static RSA privat…9.1
- CVE-2026-18755A DLL hijacking vulnerability in GeoVision GV-ASManager allo…7.3
- CVE-2026-18756HumHub Community Edition 1.18.4 contains a reflected cross-s…7.2
- CVE-2026-18759The background service of ABP or AES runs as NT AUTHORITY\SY…8.5
- CVE-2026-1876Improper Resource Shutdown or Release vulnerability in Mitsu…7.5
- CVE-2026-18765Improper neutralization of special elements used in an SQL c…9.8
Are you affected by CVE-2026-18753?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
