CVE-2025-67089

8.1

GL-iNet · GL-AXT1800 router

A command injection vulnerability in the GL-iNet GL-AXT1800 router allows authenticated attackers to execute arbitrary commands as root via the plugins.install_package RPC method.

Executive summary

A critical command injection vulnerability in GL-iNet GL-AXT1800 firmware v4.6.8 enables authenticated attackers to achieve root-level code execution on the device.

Vulnerability

This is a command injection vulnerability (CWE-78) located within the plugins.install_package RPC method, which fails to sanitize user-supplied package names. An authenticated attacker can leverage this flaw to execute arbitrary system commands with root privileges.

Business impact

The vulnerability carries a CVSS score of 8.1, reflecting a high-severity risk due to the potential for total system compromise. Successful exploitation grants an attacker full control over the router, which can be used to intercept network traffic, pivot into internal network segments, or permanently disable critical infrastructure.

Remediation

Immediate Action: Update the GL-iNet GL-AXT1800 firmware to the latest secure version provided by the manufacturer.

Proactive Monitoring: Review device logs for unusual RPC requests and monitor for unexpected binary execution or unauthorized modifications to the system configuration.

Compensating Controls: Restrict administrative access to the router management interface to trusted internal IP addresses only and disable remote management features if not strictly required.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists as documented in the security researcher's technical write-up on Medium.

Analyst recommendation

The presence of a published proof-of-concept and the high-severity impact of root-level command execution necessitates immediate action. Administrators must prioritize updating the affected GL-iNet devices to the latest patched firmware to eliminate this vector for remote code execution.

More GL-iNet CVEs

Sources