CVE-2026-18602
GL.iNet · GL-MT3000
A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.
Executive summary
A critical command injection vulnerability in the GL.iNet GL-MT3000 firmware permits unauthenticated remote attackers to execute arbitrary commands with high privileges.
Vulnerability
The vulnerability exists in the ovpn-client.get_recommend_config function within the /cgi-bin/glc file. By manipulating the Hostname argument, an unauthenticated remote attacker can trigger command injection, enabling execution of arbitrary commands on the underlying operating system.
Business impact
The ability to execute arbitrary commands remotely poses a severe threat to business operations. Attackers could gain full control over the router, facilitate lateral movement into the internal network, or deploy persistent malware. With a CVSS score of 9.8, the potential for total system compromise necessitates urgent remediation.
Remediation
Immediate Action: Update the GL.iNet GL-MT3000 firmware to the latest version provided by the vendor to eliminate the command injection vector.
Proactive Monitoring: Review system logs for suspicious process execution and monitor for anomalous outbound traffic from the router that may indicate command-and-control communication.
Compensating Controls: Implement strict firewall rules to block unauthorized access to the web administration interface from external networks until the firmware is updated.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
This vulnerability represents a critical security risk that can be exploited remotely by unauthenticated attackers. Security teams must ensure all affected GL.iNet devices are updated to the latest available firmware immediately to mitigate the risk of remote command execution and potential network-wide compromise.