CVE-2026-18616
GL-iNet · GL-MT3000
A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attackers to execute arbitrary commands.
Executive summary
Remote command injection in the GL-iNet GL-MT3000 WireGuard server component exposes the device to unauthorized remote code execution.
Vulnerability
The flaw exists in the server.set_peer function within the /cgi-bin/glc file. By manipulating the public_key argument, an unauthenticated remote attacker can trigger command injection.
Business impact
The CVSS score of 9.8 reflects the severity of this remote code execution vulnerability. Successful exploitation permits full device takeover, which could lead to network-wide compromise, data interception, and total loss of device integrity.
Remediation
Immediate Action: Update the GL-iNet GL-MT3000 device to the latest firmware version. Consult the vendor security advisory for the specific release that addresses this vulnerability.
Proactive Monitoring: Monitor for anomalous traffic or unexpected execution of system commands, particularly those related to WireGuard peer management.
Compensating Controls: Use firewall rules to isolate management interfaces and WireGuard configuration endpoints from the public internet.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.
Analyst recommendation
This vulnerability presents a severe risk to network infrastructure. IT administrators must prioritize updating all affected GL-MT3000 units to the latest firmware version to eliminate the risk of remote code execution.