{"id":"CVE-2026-18754","published":"2026-08-04T08:16:34.803","lastModified":"2026-08-04T16:16:22.133","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves an embedded RSA private key in the Lighttpd firmware, allowing attackers to decrypt HTTPS traffic and spoof the server.","exploitability":"Exploitation requires access to the device's firmware, making it moderately difficult but feasible for advanced adversaries.","blast_radius":"If exploited, this could compromise the confidentiality and integrity of all HTTPS communications on affected devices, with wide-ranging impacts.","remediation":"Update the firmware to remove or securely manage the embedded private key.","tags":["rsa","tls","encryption","web","firmware"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:44:14.215Z"}}