CVE-2026-18598

GL.iNet · GL-MT3000

A command injection vulnerability exists in the GL.iNet GL-MT3000 router, allowing authenticated users to execute arbitrary commands through the system log retrieval RPC interface.

Executive summary

A command injection vulnerability in the GL.iNet GL-MT3000 router allows authenticated attackers to execute arbitrary system commands via the log management interface.

Vulnerability

This is a command injection vulnerability (CWE-77) found within the logread system log retrieval RPC. An attacker must possess authenticated access to the device to leverage this flaw for command execution.

Business impact

Exploitation of this vulnerability grants an authenticated attacker the ability to execute commands on the underlying operating system. This could lead to a total loss of confidentiality and integrity regarding the router's operation, potentially allowing for network traffic interception or total device takeover. The CVSS score of 8.8 reflects the high severity of such an impact on network infrastructure.

Remediation

Immediate Action: Check the GL.iNet support portal for firmware updates and apply the latest version to all affected GL-MT3000 hardware as soon as it is provided.

Proactive Monitoring: Monitor system logs for unusual commands or unexpected spikes in traffic associated with the log retrieval RPC function.

Compensating Controls: Implement network segmentation to limit the exposure of the router management interface and enforce strong password policies for all authenticated users.

Exploitation status

Public Exploit Available: No (no confirmed weaponized exploit or Metasploit/ExploitDB entry identified).

Analyst recommendation

This vulnerability presents a high risk to the security of the affected GL.iNet devices. Security teams should prioritize patching as soon as the vendor provides a fix. In the interim, ensure that access to the management interface is strictly limited to authorized personnel to mitigate the risk of authenticated exploitation.