{"id":"CVE-2026-18754","published":"2026-08-04T08:16:34.803","lastModified":"2026-08-04T16:16:22.133","description":"The\nproduct firmware contains an embedded, static RSA private key utilized by the\nLighttpd web server for TLS termination. Exposure of this private key allows\nmalicious actors to breach the confidentiality and integrity of HTTPS\ncommunications, enabling traffic decryption and server spoofing.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves an embedded RSA private key in the Lighttpd web server firmware, allowing attackers to decrypt HTTPS traffic and spoof the server, compromising confidentiality and integrity.","exploitability":"Exploitation is relatively straightforward given access to the firmware, as the private key is static and embedded.","blast_radius":"If exploited, this could lead to widespread decryption of sensitive communications and spoofing attacks affecting all users of the affected Lighttpd instances.","remediation":"Disable TLS termination in Lighttpd or remove the embedded private key, and upgrade to a version that addresses this issue, such as 'Upgrade to 1.4.45 or later'.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["tls","rsa","web","encryption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:08:09.709Z"}}