{"id":"CVE-2026-18753","published":"2026-08-04T08:16:34.640","lastModified":"2026-08-04T14:16:31.280","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves an embedded RSA private key in the firmware of a Lighttpd web server used for TLS termination, which can be exploited to decrypt HTTPS traffic and spoof the server.","exploitability":"Exploitation requires access to the device's firmware, making it moderately difficult but feasible with advanced knowledge.","blast_radius":"If exploited, this vulnerability could impact any service running over HTTPS on the affected devices, leading to data breaches and potential server impersonation attacks.","remediation":"Update the firmware to remove or securely manage the embedded private key.","tags":["rsa","tls","https","decryption","spoofing"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:44:10.134Z"}}