CVE-2026-18684
GL.iNet · GL-MT3000
A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.
Executive summary
The GL.iNet GL-MT3000 device is susceptible to remote command injection, which enables unauthenticated attackers to execute arbitrary code on the system.
Vulnerability
The vulnerability originates in the remove_profile function of the /cgi-bin/glc file. It allows an unauthenticated attacker to inject and execute system commands via the web interface.
Business impact
With a CVSS score of 9.8, this vulnerability is critical. Successful exploitation provides an attacker with complete control over the affected device, potentially allowing them to pivot into internal networks, intercept traffic, or exfiltrate sensitive configuration data.
Remediation
Immediate Action: Apply the latest firmware update provided by GL.iNet to address the command injection vulnerability.
Proactive Monitoring: Review system and access logs for suspicious input strings or anomalous activity originating from the web management interface.
Compensating Controls: Restrict access to the device management interface to trusted IP addresses only, and utilize firewall rules to drop unexpected traffic directed at the /cgi-bin/glc path.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.
Analyst recommendation
Given the critical nature of this vulnerability and the presence of public exploit material, it is imperative that organizations update their GL.iNet hardware immediately. Failure to patch these devices leaves them open to total compromise by remote actors.