CVE-2026-18615
GL-iNet · GL-MT3000
An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.generate_publickey function.
Executive summary
A critical command injection flaw in the GL-iNet GL-MT3000 router enables remote, unauthenticated attackers to execute arbitrary system commands.
Vulnerability
This vulnerability resides in the wg-server.generate_publickey function within the /cgi-bin/glc interface. An attacker can manipulate the private_key argument to inject and execute arbitrary commands on the underlying operating system.
Business impact
Exploitation of this vulnerability grants the attacker full administrative control over the affected network device. This facilitates unauthorized access to sensitive internal network traffic, potential credential theft, and total compromise of the network gateway, warranting a critical severity classification based on its 9.8 CVSS score.
Remediation
Immediate Action: Update all GL-MT3000 devices to the latest firmware version released by GL-iNet to patch the vulnerable wg-server.so plugin.
Proactive Monitoring: Monitor firewall logs for unauthorized connection attempts to the router's web management interface and look for anomalous execution of system commands.
Compensating Controls: Disable remote management access on the device until a firmware update can be applied to ensure the device is not reachable from the public internet.
Exploitation status
Public Exploit Available: Yes — a public proof-of-concept exists on GitHub.
Analyst recommendation
Given the critical nature of this vulnerability and the existence of public exploit code, administrators must act immediately to secure their infrastructure. Apply the vendor-provided firmware update as the primary defense and verify device integrity post-update.