CVE-2026-18599

GL.iNet · GL-MT3000

A command injection vulnerability in the GL.iNet GL-MT3000 router allows authenticated attackers to execute arbitrary system commands.

Executive summary

A command injection vulnerability in the GL.iNet GL-MT3000 router allows an authenticated attacker to gain full control over the affected device.

Vulnerability

This vulnerability stems from improper input validation (CWE-77, CWE-74) in the device configuration logic. The attacker must possess low-level privileges (PR:L) on the local network (AV:A) to inject malicious commands into the system.

Business impact

An attacker who successfully exploits this vulnerability can achieve full system compromise, leading to data exfiltration, interception of network traffic, or the use of the device as a pivot point for further network attacks. The CVSS score of 8.0 confirms a high-risk scenario that threatens the integrity and confidentiality of the entire local network segment.

Remediation

Immediate Action: Update the GL-MT3000 firmware to the latest version provided by the manufacturer. If a patch is not yet available, restrict administrative access to the device.

Proactive Monitoring: Review system logs for unexpected command execution or modifications to configuration files that deviate from established baselines.

Compensating Controls: Disable remote administrative access and ensure that the web management interface is only accessible from trusted, segmented management VLANs.

Exploitation status

Public Exploit Available: Yes (GitHub PoC repository)

Analyst recommendation

Given the availability of proof-of-concept code and the high potential for total system compromise, users of the GL-MT3000 should treat this as a high-priority update. Ensure that all firmware updates are obtained directly from the vendor to maintain device security.