{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18686/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-18686"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GL-MT3000"],"_cs_severities":["critical"],"_cs_tags":["cve-2026-18686","command-injection","iot","rce"],"_cs_type":"threat","_cs_vendors":["GL.iNet"],"content_html":"\u003cp\u003eA critical command injection vulnerability, identified as CVE-2026-18686, affects the GL.iNet GL-MT3000 router running firmware versions up to and including 4.4.5. The vulnerability resides within the 'nas-web.add_user' function of the 'nas-web' RPC wrapper, which is accessible via the '/cgi-bin/glc' endpoint.\u003c/p\u003e\n\u003cp\u003eThe flaw allows an unauthenticated, remote attacker to trigger command injection by manipulating inputs sent to this specific RPC handler. Because this interface is reachable over the network, it presents a significant risk to affected devices. Proof-of-concept (PoC) exploit code is publicly available, increasing the likelihood of exploitation. This vulnerability is categorized under CWE-77 (Improper Neutralization of Special Elements used in a Command). Given the high base CVSS score, owners of these devices are advised to update firmware immediately upon the availability of security patches.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify GL.iNet GL-MT3000 devices exposing the web administration interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request directed at the '/cgi-bin/glc' endpoint.\u003c/li\u003e\n\u003cli\u003eThe request targets the 'nas-web.add_user' function within the nas-web RPC wrapper.\u003c/li\u003e\n\u003cli\u003eThe attacker injects shell metacharacters into the input parameters expected by the function.\u003c/li\u003e\n\u003cli\u003eThe application fails to sanitize the input, passing the attacker-supplied string directly to a system-level command execution routine.\u003c/li\u003e\n\u003cli\u003eThe router executes the injected commands with the privileges of the web service process.\u003c/li\u003e\n\u003cli\u003eFinal objective: The attacker gains remote code execution on the device, potentially leading to full system compromise or persistence.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary command execution on the router with high-level privileges. This enables attackers to reconfigure the network device, exfiltrate sensitive configuration data, pivot into internal networks protected by the router, or deploy persistent malware. The vulnerability affects all users of GL-MT3000 running firmware version 4.4.5 or earlier, significantly increasing the attack surface for remote compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade GL-MT3000 firmware to the latest available version provided by GL.iNet to patch CVE-2026-18686.\u003c/li\u003e\n\u003cli\u003eRestrict access to the device web administration interface (/cgi-bin/glc) to trusted management IP addresses via internal firewall rules.\u003c/li\u003e\n\u003cli\u003eEnable ingress monitoring on the network perimeter to identify HTTP POST requests directed at '/cgi-bin/glc' containing unexpected characters or command sequences (e.g., semicolons, pipe symbols, backticks).\u003c/li\u003e\n\u003cli\u003eReview network logs for unusual outbound connections originating from GL-MT3000 routers, which may indicate post-exploitation activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T01:42:26Z","date_published":"2026-08-04T01:42:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-glinet-rce/","summary":"A critical command injection vulnerability in the nas-web RPC Wrapper of GL.iNet GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands via the /cgi-bin/glc interface.","title":"Remote Command Injection Vulnerability in GL.iNet GL-MT3000","url":"https://feed.craftedsignal.io/briefs/2026-08-glinet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18686","version":"https://jsonfeed.org/version/1.1"}