Vulnerabilidad · Publicado 04/08/2026
El firmware de múltiples dispositivos contiene una clave RSA privada estática utilizada por el servidor web Lighttpd para terminación TLS. La exposición de esta clave permite a atacantes descifrar comunicaciones HTTPS, suplantar servidores y comprometer la confidencialidad e integridad de datos sensibles en tránsito. Impacta infraestructuras críticas y plataformas de comercio electrónico en LATAM que dependen de este servicio web.
The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and server spoofing.
Score: 9.1/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-321
Publicado en NIST NVD.