CVE-2026-18612
GL-iNet · GL-MT3000
A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the package management functions.
Executive summary
A critical command injection vulnerability in the GL-iNet GL-MT3000 router permits unauthenticated remote attackers to gain full system control.
Vulnerability
The flaw exists in the plugins.remove_package and plugins.install_package functions within the /cgi-bin/glc file. Attackers can leverage this to perform command injection, leading to unauthenticated remote code execution.
Business impact
Successful exploitation poses a severe risk, as it allows attackers to bypass authentication and execute commands with elevated privileges. This can result in complete loss of confidentiality, integrity, and availability for the affected network segment, justifying the 9.8 CVSS score.
Remediation
Immediate Action: Apply the latest firmware update for the GL-MT3000 provided by GL-iNet to resolve the vulnerability in the plugins.so module.
Proactive Monitoring: Inspect system logs for unexpected package management activities or unauthorized command execution events.
Compensating Controls: Restrict access to the web-based management interface by using network segmentation or firewall rules that limit access to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.
Analyst recommendation
The presence of exploit code and the critical nature of this vulnerability make it a high priority for remediation. Administrators should verify their device firmware version immediately and apply the necessary patches to protect against potential remote exploitation.