<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>GL-MT3000 (Firmware &lt;= 4.4.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/gl-mt3000-firmware--4.4.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 04 Aug 2026 01:42:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/gl-mt3000-firmware--4.4.5/feed.xml" rel="self" type="application/rss+xml"/><item><title>Remote Command Injection in GL.iNet GL-MT3000</title><link>https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/</link><pubDate>Tue, 04 Aug 2026 01:42:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/</guid><description>An unauthenticated remote command injection vulnerability in the GL.iNet GL-MT3000 router allows arbitrary code execution via the /cgi-bin/glc component.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-18685) has been identified in the GL.iNet GL-MT3000 router, specifically within the <code>set_upgrade</code> function located in the <code>modem.so</code> component, invoked via <code>/cgi-bin/glc</code>. This flaw enables unauthenticated, remote attackers to perform command injection, leading to full system compromise. The vulnerability affects firmware versions up to 4.4.5. Publicly available exploit code has been disclosed, significantly lowering the barrier for exploitation by malicious actors. Given the remote accessibility of the target interface and the availability of proof-of-concept material, organizations deploying this hardware should prioritize applying firmware updates or restricting access to the management interface.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies an internet-facing GL.iNet GL-MT3000 router.</li>
<li>The attacker sends a crafted HTTP request to the target device.</li>
<li>The request targets the <code>/cgi-bin/glc</code> binary.</li>
<li>The input is passed to the vulnerable <code>set_upgrade</code> function within <code>modem.so</code> without proper sanitization.</li>
<li>The <code>set_upgrade</code> function processes the malicious input, leading to command injection.</li>
<li>The injected commands are executed by the underlying operating system.</li>
<li>The attacker achieves arbitrary code execution with elevated privileges on the router.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full remote control of the affected router. Attackers can leverage the compromised device to intercept network traffic, gain a foothold in the local network, or use the device as part of a botnet. Given the nature of these routers, this compromise presents a significant risk to the privacy and security of all connected clients.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all GL.iNet GL-MT3000 devices in the environment and verify the currently installed firmware version.</li>
<li>Patch affected devices to the latest firmware version released by GL.iNet immediately to mitigate CVE-2026-18685.</li>
<li>Restrict access to the router's web management interface to trusted internal management subnets.</li>
<li>Monitor edge device traffic for unusual HTTP requests targeting <code>/cgi-bin/glc</code> originating from external sources.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>rce</category><category>iot</category><category>router</category></item></channel></rss>