---
id: CVE-2026-18754
title: |-
  The
  product firmware contains an embedded, static RSA private key utilized by the
  Lighttpd web server for TLS termination
summary: |-
  The
  product firmware contains an embedded, static RSA private key utilized by the
  Lighttpd web server for TLS termination. Exposure of this private key allows
  malicious actors to breach the confidentiality and integrity of HTTPS
  communic…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-321
published: '2026-08-04'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:41:02.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18754'
references:
  - url: 'https://www.geovision.com.tw/cyber_security.php'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
tags:
  - nvd
epss: 0.00313
epssPercentile: 0.24416
ingestedAt: '2026-09-09T16:14:05.511Z'
---

## Overview

The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web server for TLS termination. Exposure of this private key allows
malicious actors to breach the confidentiality and integrity of HTTPS
communications, enabling traffic decryption and server spoofing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
