CVE-2026-18600

GL.iNet · GL-MT3000

A command injection vulnerability exists in the GL.iNet GL-MT3000 router that allows authenticated users to execute arbitrary system commands via the network switch information RPC interface.

Executive summary

A command injection vulnerability in the GL.iNet GL-MT3000 router allows authenticated attackers to achieve remote code execution on affected devices.

Vulnerability

This is a command injection vulnerability (CWE-77) triggered via the network switch information RPC. The vulnerability requires the attacker to have low-level authenticated access to the device to execute arbitrary commands.

Business impact

Successful exploitation of this vulnerability allows an authenticated attacker to execute arbitrary commands with system privileges. This can lead to full device compromise, potential lateral movement within the local network, and the exfiltration of sensitive configuration data. Given the CVSS score of 8.8, this poses a significant risk to network integrity and confidentiality.

Remediation

Immediate Action: Monitor official vendor communication channels for the release of a firmware update and apply it immediately upon availability.

Proactive Monitoring: Review device access logs for suspicious RPC calls or unauthorized attempts to access network configuration parameters.

Compensating Controls: Restrict administrative access to the router interface to trusted IP addresses only and disable remote management features if they are not required for business operations.

Exploitation status

Public Exploit Available: No (no confirmed weaponized exploit or Metasploit/ExploitDB entry identified).

Analyst recommendation

The severity of this command injection flaw necessitates immediate attention. Administrators should restrict access to the management interface to minimize the attack surface while awaiting a vendor-supplied firmware patch. Once a patch is released, prioritize its deployment to all managed GL-MT3000 units to prevent potential remote code execution.