CVE-2026-18613

GL-iNet · GL-MT3000

A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attackers to execute arbitrary code.

Executive summary

A critical injection vulnerability in the GL-iNet GL-MT3000 router firmware allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

The flaw resides in the plugins.set_config function within the /cgi-bin/glc file of the plugins.so native plugin. This vulnerability permits unauthenticated remote attackers to inject malicious input, leading to potential full system control.

Business impact

Successful exploitation of this vulnerability grants an attacker total administrative control over the affected router. This could lead to complete network interception, unauthorized access to internal resources, and significant data exfiltration. Given the CVSS score of 9.8, this risk is classified as critical, as it requires no authentication and can be triggered remotely.

Remediation

Immediate Action: Check the official GL-iNet support portal for firmware updates addressing this vulnerability and apply the latest available version immediately.

Proactive Monitoring: Monitor network traffic for unusual requests directed at the /cgi-bin/glc endpoint and review device access logs for unexpected configuration changes.

Compensating Controls: If a patch is not immediately available, restrict management access to the router interface to trusted internal IP addresses only, and disable remote web administration if not strictly required.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability and the availability of proof-of-concept code, immediate action is required. Organizations using the GL-MT3000 should verify their firmware version and prioritize the application of vendor patches to prevent potential remote code execution and full device takeover.