21 Total CVEs
21 AI Analyzed
0 CISA KEV
12 Critical

Profile

0% ended up actively exploited 0 of 21 added to CISA KEV
57% rated critical (CVSS 9.0+) 12 critical, 9 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

21 CVEs in the last 12 months

Products

  • GL-MT300013
  • A1300, AX1800, AXT1800, BE1400, BE3600, BE65003
  • GL-AR300M161
  • A1300, AX1800, AXT1800, MT2500, MT3000, MT60001
  • BE9300, MT60001
  • AX18001

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-21 of 21 CVEs
CVE-2026-26793
Analyzed
9.8
GL.iNet GL-AR300M16

The GL-iNet GL-AR300M16 router contains a command injection vulnerability in the `set_config` function, allowing for arbitrary command execution.

2026-03-13
CVE-2026-19983
Analyzed
8.3
GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000

A vulnerability was detected in GL

2026-08-17
CVE-2026-19982
Analyzed
7.4
GL.iNet BE9300, MT6000

A security vulnerability has been detected in GL

2026-08-18
CVE-2026-19981
Analyzed
7.4
GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500

A weakness has been identified in GL

2026-08-18
CVE-2026-19980
Analyzed
7.4
GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500

A security flaw has been discovered in GL

2026-08-18
CVE-2026-19979
Analyzed
8.3
GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500

A vulnerability was identified in GL

2026-08-17
CVE-2026-18787
Analyzed
8.8
GL.iNet AX1800

A vulnerability was identified in GL

2026-08-05
CVE-2026-18686
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system c...

2026-08-04
CVE-2026-18685
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to...

2026-08-04
CVE-2026-18684
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers...

2026-08-04
CVE-2026-18616
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attacker...

2026-08-04
CVE-2026-18615
Analyzed
9.8
GL.iNet GL-MT3000

An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.ge...

2026-08-04
CVE-2026-18614
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands...

2026-08-04
CVE-2026-18613
Analyzed
9.8
GL.iNet GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attacker...

2026-08-04
CVE-2026-18612
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary co...

2026-08-04
CVE-2026-18602
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attacker...

2026-08-04
CVE-2026-18601
Analyzed
9.8
GL.iNet GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via...

2026-08-04
CVE-2026-18600
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability has been found in GL

2026-08-04
CVE-2026-18599
Analyzed
8
GL.iNet GL-MT3000

A flaw has been found in GL

2026-08-04
CVE-2026-18598
Analyzed
8.8
GL.iNet GL-MT3000

A vulnerability was detected in GL

2026-08-04
CVE-2023-46453
Analyzed
9.8
GL.iNet Multiple Products

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both...

2026-05-09