PT-2026-47149 · Gl.Inet · Mt3000

·

CVE-2026-11406

·

Published

2026-05-06

·

Updated

2026-06-06

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GL.iNet MT3000 versions prior to 4.9.0 beta3-1012-0513-1778656146
Description Command injection is possible in the OpenVPN Client Import Workflow component via the ovpnclient.sh file. This issue allows remote exploitation when malicious OpenVPN configuration files are processed.
Recommendations Upgrade to version 4.9.0 beta3-1012-0513-1778656146.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07964
CVE-2026-11406

Affected Products

Mt3000