PT-2026-67396 · Gl.Inet · Gl-Mt3000
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GL.iNet GL-MT3000 versions prior to 4.4.6
Description
The Network Lua RPC Plugin contains a flaw that allows remote command injection. The issue exists within the
network.switch info() and network.switch status() functions located in the /usr/lib/oui-httpd/rpc/network file. An attacker can trigger this by manipulating the switch argument.Recommendations
Update GL.iNet GL-MT3000 to version 4.4.6 or later.
As a temporary workaround, restrict access to the Network Lua RPC Plugin to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gl-Mt3000