PT-2026-67482 · Gl.Inet · Gl-Mt3000

·

CVE-2026-18616

·

Published

2026-08-03

·

Updated

2026-08-10

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GL-iNet GL-MT3000 versions prior to 4.4.6
Description Command injection is possible via remote exploitation in the wg-server.so Native Plugin. The issue exists within the server.set peer() function located in the /cgi-bin/glc file, where improper handling of the public key variable allows for the execution of arbitrary commands.
Recommendations Update GL-iNet GL-MT3000 to version 4.4.6 or later. As a temporary mitigation, restrict access to the /cgi-bin/glc endpoint to prevent unauthorized manipulation of the public key variable.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18616

Affected Products

Gl-Mt3000