PT-2026-67463 · Gl.Inet · Gl-Mt3000
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GL-iNet GL-MT3000 versions prior to 4.4.6
Description
Remote command injection is possible within the s2s.so Native Plugin. The issue exists in the
s2s.enable echo server() function located in the /cgi-bin/glc file. An attacker can trigger this by manipulating the port argument, allowing for the execution of arbitrary commands on the system.Recommendations
Update to a version newer than 4.4.5.
As a temporary mitigation, restrict access to the
/cgi-bin/glc endpoint or avoid using the port argument within the s2s.enable echo server() function.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gl-Mt3000