CVE-2026-18616

GL-iNet · GL-MT3000

A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attackers to execute arbitrary commands.

Executive summary

Remote command injection in the GL-iNet GL-MT3000 WireGuard server component exposes the device to unauthorized remote code execution.

Vulnerability

The flaw exists in the server.set_peer function within the /cgi-bin/glc file. By manipulating the public_key argument, an unauthenticated remote attacker can trigger command injection.

Business impact

The CVSS score of 9.8 reflects the severity of this remote code execution vulnerability. Successful exploitation permits full device takeover, which could lead to network-wide compromise, data interception, and total loss of device integrity.

Remediation

Immediate Action: Update the GL-iNet GL-MT3000 device to the latest firmware version. Consult the vendor security advisory for the specific release that addresses this vulnerability.

Proactive Monitoring: Monitor for anomalous traffic or unexpected execution of system commands, particularly those related to WireGuard peer management.

Compensating Controls: Use firewall rules to isolate management interfaces and WireGuard configuration endpoints from the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

This vulnerability presents a severe risk to network infrastructure. IT administrators must prioritize updating all affected GL-MT3000 units to the latest firmware version to eliminate the risk of remote code execution.