{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/gl-mt3000/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18598"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GL-MT3000"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","command-injection","cve-2026-18598","iot-security","cve-2026-18599","router","rce","cve-2026-18601","iot"],"_cs_type":"advisory","_cs_vendors":["GL.iNet"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-18598) exists in the GL.iNet GL-MT3000 wireless router, affecting firmware versions up to 4.4.5. The vulnerability is located within the Logread Lua RPC plugin, specifically in the \u003ccode\u003elogread.get_system_log\u003c/code\u003e function handled by the \u003ccode\u003e/usr/lib/oui-httpd/rpc/logread\u003c/code\u003e file. An authenticated remote attacker can manipulate the \u003ccode\u003emodule\u003c/code\u003e argument to inject and execute arbitrary system commands on the underlying host operating system. This vulnerability stems from improper neutralization of special elements used in command execution (CWE-77). Public exploit code for this flaw is available, significantly lowering the barrier for exploitation. Given the network-facing nature of these devices, organizations should prioritize updating to a patched firmware version or restricting access to the management RPC interface.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable GL.iNet management interfaces.\u003c/li\u003e\n\u003cli\u003eAttacker obtains valid low-privileged credentials for the GL-MT3000 web management portal.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the OUI-based RPC service endpoint used by the Logread Lua RPC plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing a payload injected into the \u003ccode\u003emodule\u003c/code\u003e argument of the \u003ccode\u003elogread.get_system_log\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eoui-httpd\u003c/code\u003e service processes the request and passes the tainted \u003ccode\u003emodule\u003c/code\u003e argument to the system shell.\u003c/li\u003e\n\u003cli\u003eThe system shell executes the attacker-supplied commands with the privileges of the web service process.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution for persistence, further system exploitation, or network traversal.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated (if PR is bypassed) or low-privileged remote attackers to gain full control over the router. This can lead to complete compromise of the network traffic passing through the device, unauthorized exfiltration of sensitive information, or the potential for lateral movement into the internal network protected by the router.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate GL-MT3000 firmware to version 4.4.6 or later immediately to patch CVE-2026-18598.\u003c/li\u003e\n\u003cli\u003eDisable remote access to the web management interface on all internet-facing GL.iNet devices.\u003c/li\u003e\n\u003cli\u003eImplement strictly limited access control lists (ACLs) for the device management interface.\u003c/li\u003e\n\u003cli\u003eMonitor network logs for unusual HTTP POST requests to \u003ccode\u003e/rpc/logread\u003c/code\u003e or similar paths containing shell metacharacters such as semicolon, pipe, or backticks in query parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T16:04:58Z","date_published":"2026-08-03T14:03:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/","summary":"A command injection vulnerability in the Logread Lua RPC plugin of GL.iNet GL-MT3000 firmware versions 4.4.5 and earlier allows authenticated remote attackers to execute arbitrary system commands via the module argument.","title":"Remote Command Injection in GL.iNet GL-MT3000 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - GL-MT3000","version":"https://jsonfeed.org/version/1.1"}