CVE-2026-18754

Die Produkt-Firmware enthält einen eingebetteten, statischen RSA-Schlüssel privater Art, der vom Lighttpd-Webserver für die TLS-Terminier…

criticalEPSS 0.4%

Description

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.

Metrics

9.1
Source: nvd-v3
36.3 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-04 07:09 UTC
CWE-321

Weakness classes (CWE)

  • CWE-321Variant

    Use of Hard-coded Cryptographic Key

    The product uses a hard-coded, unchangeable cryptographic key.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-04 16:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-18754","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-08-04 08:16 UTC· 0df08a0e-a200-4957-9bb0-084f562506f9
    • Affected: GV-AS1620 (GV-Cloud)
    • Description: The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    • CWE: CWE-321

Linked advisories