{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18612/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18612"},{"cvss":9.8,"id":"CVE-2026-18613"},{"cvss":9.8,"id":"CVE-2026-18616"},{"cvss":9.8,"id":"CVE-2026-18614"},{"cvss":9.8,"id":"CVE-2026-18615"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["GL-MT3000","GL-MT3000 (\u003c= 4.4.5)"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-18612","remote-code-execution","command-injection","router","cve-2026-18614","network-device","rce","network-security","cve-2026-18615"],"_cs_type":"advisory","_cs_vendors":["GL-iNet"],"content_html":"\u003cp\u003eA critical security vulnerability (CVE-2026-18612) has been identified in the GL-iNet GL-MT3000 router firmware, affecting all versions up to and including 4.4.5. The vulnerability resides within the 'plugins.so' native plugin, specifically impacting the 'plugins.remove_package' and 'plugins.install_package' functions invoked via the '/cgi-bin/glc' CGI binary. An unauthenticated, remote attacker can leverage this flaw to perform command injection, resulting in full remote code execution on the device.\u003c/p\u003e\n\u003cp\u003ePublic exploit code has been released, significantly lowering the barrier for exploitation. Given the prevalence of this hardware in edge and small-office network environments, organizations utilizing these devices should prioritize patching or restricting access to the management interface. The vendor has acknowledged the flaw, and users are advised to update to the latest available firmware version that addresses this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 base score of 9.8 (Critical), indicating high risk for confidentiality, integrity, and availability. Successful exploitation grants an attacker administrative control over the router, enabling further network compromise, traffic interception, or the deployment of persistent implants within the affected network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate GL-iNet GL-MT3000 firmware to the latest version immediately to remediate CVE-2026-18612.\u003c/li\u003e\n\u003cli\u003eRestrict access to the router's web management interface to trusted internal IP ranges or VPNs.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall or IDS/IPS signatures capable of detecting anomalous POST requests targeting '/cgi-bin/glc' with suspicious shell metacharacters (e.g., ;, |, \u0026amp;\u0026amp;).\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious attempts to access the vulnerable CGI binary.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T20:06:20Z","date_published":"2026-08-03T20:05:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/","summary":"A critical command injection vulnerability in the GL-iNet GL-MT3000 router firmware (up to 4.4.5) allows remote, unauthenticated attackers to execute arbitrary commands via the /cgi-bin/glc binary.","title":"Remote Command Injection in GL-iNet GL-MT3000 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18612","version":"https://jsonfeed.org/version/1.1"}