PT-2026-67144 · Gl.Inet · Be9300+10

·

CVE-2026-18585

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GL.iNet MT3000 versions prior to 20260707 GL.iNet MT6000 versions prior to 20260707 GL.iNet BE9300 versions prior to 20260707 GL.iNet BE3600 versions prior to 20260707 GL.iNet MT3600BE versions prior to 20260707 GL.iNet E5800 versions prior to 20260707 GL.iNet BE6500 versions prior to 20260707 GL.iNet MT5000 versions prior to 20260707 GL.iNet X3000 versions prior to 20260707 GL.iNet XE3000 versions prior to 20260707 GL.iNet MT2500 versions prior to 20260707
Description A remote attack can trigger a heap-based buffer overflow, which occurs when a program writes more data to a heap memory area than it can hold, potentially leading to crashes or arbitrary code execution. This issue exists within the APPS-NAS Module, specifically in the nas-web.get file list() function.
Recommendations Update MT3000 to version 20260707 or later. Update MT6000 to version 20260707 or later. Update BE9300 to version 20260707 or later. Update BE3600 to version 20260707 or later. Update MT3600BE to version 20260707 or later. Update E5800 to version 20260707 or later. Update BE6500 to version 20260707 or later. Update MT5000 to version 20260707 or later. Update X3000 to version 20260707 or later. Update XE3000 to version 20260707 or later. Update MT2500 to version 20260707 or later. As a temporary workaround, restrict access to the nas-web.get file list() function within the APPS-NAS Module.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18585

Affected Products

Be3600
Be6500
Be9300
E5800
Mt2500
Mt3000
Mt3600Be
Mt5000
Mt6000
X3000
Xe3000