PT-2026-67396 · Gl.Inet · Gl-Mt3000

·

CVE-2026-18600

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GL.iNet GL-MT3000 versions prior to 4.4.6
Description The Network Lua RPC Plugin contains a flaw that allows remote command injection. The issue exists within the network.switch info() and network.switch status() functions located in the /usr/lib/oui-httpd/rpc/network file. An attacker can trigger this by manipulating the switch argument.
Recommendations Update GL.iNet GL-MT3000 to version 4.4.6 or later. As a temporary workaround, restrict access to the Network Lua RPC Plugin to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18600

Affected Products

Gl-Mt3000