CVE-2026-18685

GL.iNet · GL-MT3000

A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.

Executive summary

The GL.iNet GL-MT3000 device is vulnerable to remote command injection, posing a critical risk of full system compromise.

Vulnerability

The vulnerability exists in the set_upgrade function within the /cgi-bin/glc binary. It allows an unauthenticated remote attacker to inject malicious commands due to improper input validation.

Business impact

A successful exploit allows an attacker to execute arbitrary commands with the privileges of the web service, leading to full system takeover. Given the CVSS score of 9.8, this vulnerability represents a critical risk that could result in complete loss of device confidentiality, integrity, and availability, potentially facilitating lateral movement within the network.

Remediation

Immediate Action: Update the GL.iNet GL-MT3000 firmware to the latest available version provided by the vendor to remediate the injection flaw.

Proactive Monitoring: Monitor device logs for unusual shell execution patterns or unauthorized requests directed at the /cgi-bin/glc endpoint.

Compensating Controls: Implement strict network access controls or a Web Application Firewall to block unauthorized access to the web interface from untrusted networks until the device is patched.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

The severity of this vulnerability, combined with the availability of public exploit code, necessitates immediate action. Administrators should prioritize firmware updates for all affected GL-MT3000 devices to prevent potential remote code execution.