What is CVE-2026-18753?
This vulnerability stems from an embedded, static RSA private key in the product's firmware used by the Lighttpd web server for TLS termination. Exposure of this key allows attackers to decrypt HTTPS traffic and spoof the server, compromising communication confidentiality and integrity.
Azərbaycanca: Bu boşluq cihaz proqram təminatında yerləşdirilmiş statik RSA özəl açarı ilə bağlıdır. Bu açar Lighttpd veb serveri tərəfindən TLS üçün istifadə olunur, onun ifşası HTTPS trafikinin deşifrə edilməsinə və server saxtalaşdırılmasına imkan yaradır.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
What attacks against TLS traffic can an attacker perform by exploiting CVE-2026-18753?
An attacker can decrypt HTTPS traffic and spoof the server, compromising communication confidentiality and integrity.
What is the root cause of CVE-2026-18753?
The vulnerability stems from an embedded, static RSA private key in the product's firmware used by the Lighttpd web server for TLS termination.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.