CVE-2026-18614

GL-iNet · GL-MT3000

A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the s2s.enable_echo_server function.

Executive summary

A critical command injection vulnerability in the GL-iNet GL-MT3000 router allows unauthenticated remote attackers to achieve full system compromise.

Vulnerability

The vulnerability exists in the s2s.enable_echo_server function within the /cgi-bin/glc interface. By manipulating the port argument, an unauthenticated attacker can inject and execute arbitrary system commands.

Business impact

Successful exploitation allows an attacker to gain full control over the router, leading to potential data theft, network interception, or the use of the device as a pivot point for further lateral movement within the internal network. Given the CVSS score of 9.8, this vulnerability represents a maximum severity threat to organizational security and infrastructure integrity.

Remediation

Immediate Action: Identify all GL-MT3000 devices running affected firmware and update them to the latest available version provided by the vendor.

Proactive Monitoring: Review device access logs for suspicious requests directed at /cgi-bin/glc or unusual traffic patterns originating from the router.

Compensating Controls: Deploy a Web Application Firewall or network access control list to restrict access to the device management interface from untrusted or external networks.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.

Analyst recommendation

The severity of this vulnerability, combined with the availability of public proof-of-concept code, necessitates immediate patching. Organizations should prioritize updating all affected GL-iNet devices and restrict administrative access to mitigate the risk of remote code execution.