{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/gl-mt3000-firmware--4.4.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18685"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GL-MT3000 (Firmware \u003c= 4.4.5)"],"_cs_severities":["critical"],"_cs_tags":["cve","rce","iot","router"],"_cs_type":"advisory","_cs_vendors":["GL.iNet"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-18685) has been identified in the GL.iNet GL-MT3000 router, specifically within the \u003ccode\u003eset_upgrade\u003c/code\u003e function located in the \u003ccode\u003emodem.so\u003c/code\u003e component, invoked via \u003ccode\u003e/cgi-bin/glc\u003c/code\u003e. This flaw enables unauthenticated, remote attackers to perform command injection, leading to full system compromise. The vulnerability affects firmware versions up to 4.4.5. Publicly available exploit code has been disclosed, significantly lowering the barrier for exploitation by malicious actors. Given the remote accessibility of the target interface and the availability of proof-of-concept material, organizations deploying this hardware should prioritize applying firmware updates or restricting access to the management interface.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an internet-facing GL.iNet GL-MT3000 router.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted HTTP request to the target device.\u003c/li\u003e\n\u003cli\u003eThe request targets the \u003ccode\u003e/cgi-bin/glc\u003c/code\u003e binary.\u003c/li\u003e\n\u003cli\u003eThe input is passed to the vulnerable \u003ccode\u003eset_upgrade\u003c/code\u003e function within \u003ccode\u003emodem.so\u003c/code\u003e without proper sanitization.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eset_upgrade\u003c/code\u003e function processes the malicious input, leading to command injection.\u003c/li\u003e\n\u003cli\u003eThe injected commands are executed by the underlying operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary code execution with elevated privileges on the router.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote control of the affected router. Attackers can leverage the compromised device to intercept network traffic, gain a foothold in the local network, or use the device as part of a botnet. Given the nature of these routers, this compromise presents a significant risk to the privacy and security of all connected clients.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all GL.iNet GL-MT3000 devices in the environment and verify the currently installed firmware version.\u003c/li\u003e\n\u003cli\u003ePatch affected devices to the latest firmware version released by GL.iNet immediately to mitigate CVE-2026-18685.\u003c/li\u003e\n\u003cli\u003eRestrict access to the router's web management interface to trusted internal management subnets.\u003c/li\u003e\n\u003cli\u003eMonitor edge device traffic for unusual HTTP requests targeting \u003ccode\u003e/cgi-bin/glc\u003c/code\u003e originating from external sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T01:42:16Z","date_published":"2026-08-04T01:42:16Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/","summary":"An unauthenticated remote command injection vulnerability in the GL.iNet GL-MT3000 router allows arbitrary code execution via the /cgi-bin/glc component.","title":"Remote Command Injection in GL.iNet GL-MT3000","url":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - GL-MT3000 (Firmware \u003c= 4.4.5)","version":"https://jsonfeed.org/version/1.1"}