Multiple unauthenticated remote command injection vulnerabilities in the GL.iNet GL-MT3000 router allow arbitrary code execution via the /cgi-bin/glc component. Public exploit code is available; patch firmware immediately.
exploited
GL-MT3000
cve
rce
iot
router
cve-2026-18686
command-injection
1r
3t
2c
2i
updated