CVE-2026-18686

GL.iNet · GL-MT3000

A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system commands via the add_user function.

Executive summary

A critical command injection vulnerability in GL.iNet GL-MT3000 routers enables remote, unauthenticated attackers to execute arbitrary commands, posing a severe risk of device compromise.

Vulnerability

The nas-web RPC wrapper function, specifically add_user, fails to sanitize user inputs, resulting in a command injection vulnerability (CWE-77). This allows unauthenticated remote attackers to execute system-level commands on the router.

Business impact

An attacker gaining command execution on a router can intercept network traffic, redirect DNS queries, or use the device as a pivot point to attack internal network resources. With a CVSS score of 9.8, this flaw represents a severe threat to network security and data privacy for all users relying on the affected hardware.

Remediation

Immediate Action: Update the firmware of GL-MT3000 devices to the latest available version provided by the vendor.

Proactive Monitoring: Monitor device logs for unusual system activity, unauthorized user creation, or unexpected outbound connections from the router management interface.

Compensating Controls: Restrict access to the router web management interface (nas-web) to trusted internal IP addresses only, and disable remote management features if not required.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

The presence of a public proof-of-concept necessitates an urgent response. All GL-MT3000 devices must be patched immediately to prevent exploitation. If a patch cannot be applied, ensure the device management interface is not exposed to the public internet.