CVE-2026-18754
Die Produkt-Firmware enthält einen eingebetteten, statischen RSA-Schlüssel privater Art, der vom Lighttpd-Webserver für die TLS-Terminier…
criticalEPSS 0.4%
Description
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Source: NVD (NIST)cvelistv5
Metrics
Show all metrics
Severity
critical
80.16
no public PoC known
9.1
Published
2026-08-04 07:09 UTC
CWE-321
Weakness classes (CWE)
CWE-321Variant
Use of Hard-coded Cryptographic Key
The product uses a hard-coded, unchangeable cryptographic key.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-04 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-18754","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-08-04 08:16 UTC· 0df08a0e-a200-4957-9bb0-084f562506f9
- Affected: GV-AS1620 (GV-Cloud)
- Description: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- CWE: CWE-321