What is CVE-2026-18754?
The product firmware contains an embedded, static RSA private key used by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach HTTPS communication confidentiality and integrity. Affected devices should be updated with patched firmware to mitigate the risk of traffic decryption and server spoofing.
Azərbaycanca: Məhsulun proqram təminatında quraşdırılmış statik RSA özəl açarı var, hansı ki, Lighttpd veb serveri tərəfindən TLS üçün istifadə olunur. Bu özəl açarın ifşası HTTPS rabitəsinin məxfiliyini və bütövlüyünü pozmağa imkan verir. Potensial olaraq trafikin deşifrə edilməsi və serverin saxtalaşdırılması riskini aradan qaldırmaq üçün təsirlənmiş cihazlarda proqram təminatı yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ2
What is the CVE-2026-18754 vulnerability?
This vulnerability involves an embedded, static RSA private key in the product firmware used by the Lighttpd web server for TLS termination. Exposure of this key allows breaching the confidentiality and integrity of HTTPS communication.
How can I protect against CVE-2026-18754?
To eliminate the risk of traffic decryption and server spoofing, affected devices should be updated with patched firmware.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.